CVE-1999-0697: High severity SCO OpenServer vulnerability
SCO Doctor allows local users to gain root privileges through a Tools option.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SCO Doctorfrom your environment.Uninstall SCO Doctor from affected SCO OpenServer systems if the product is not required.
- Configuration
Disable the Tools option in SCO Doctor (remove or restrict access to the Tools menu/feature) to prevent local users from using it to gain root privileges.
SCO Doctor Tools option = disabled - Compensating control
Restrict local access to hosts running SCO Doctor to trusted administrators only (lock down accounts, remove unneeded local user accounts, and restrict interactive logins) until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0697?
CVE-1999-0697 is considered critical due to the potential for local users to gain root privileges.
How do I fix CVE-1999-0697?
To fix CVE-1999-0697, ensure that you apply the latest patches and updates for SCO OpenServer version 5.0.4 and 5.0.5.
Who is affected by CVE-1999-0697?
CVE-1999-0697 affects local users of Xinuos OpenServer versions 5.0.4 and 5.0.5.
What are the implications of CVE-1999-0697?
The implications of CVE-1999-0697 include unauthorized escalation of privileges, potentially compromising the system security.
Is CVE-1999-0697 a remote or local vulnerability?
CVE-1999-0697 is a local vulnerability, meaning it can only be exploited by users with access to the system.