CVE-1999-0830: Buffer Overflow
Buffer overflow in SCO UnixWare Xsco command via a long argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SCO UnixWare Xsco commandfrom your environment.Remove or disable the Xsco command on affected UnixWare systems until a vendor-provided patch or fixed version is available.
- Compensating control
Restrict access and execution of the Xsco command to trusted administrators only (for example via file permissions, sudoers, host-based ACLs) and restrict network access to hosts offering this service using firewall rules to trusted IPs.
- Operational
Audit system logs for invocations of the Xsco command and for unusually long command arguments; isolate and investigate any hosts showing suspicious activity or signs of exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0830?
CVE-1999-0830 is classified as a high-severity vulnerability due to its potential to cause a buffer overflow.
How do I fix CVE-1999-0830?
To fix CVE-1999-0830, apply the available patches from Xinuos for UnixWare 7.0.
What systems are affected by CVE-1999-0830?
CVE-1999-0830 affects SCO UnixWare version 7.0.
What type of vulnerability is CVE-1999-0830?
CVE-1999-0830 is a buffer overflow vulnerability that can be exploited via a long argument supplied to the Xsco command.
Is there any exploit for CVE-1999-0830?
Yes, CVE-1999-0830 can be exploited by providing crafted input that exceeds the buffer size, potentially allowing arbitrary code execution.