CVE-1999-0893: Low severity SCO OpenServer vulnerability
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SCO OpenServer/userOsafrom your environment.Uninstall or remove the userOsa component if it is not required.
- Compensating control
Restrict access to the userOsa binary and any directories it writes to so unprivileged local users cannot create or follow symlinks there (apply filesystem permissions, ACLs, or other access controls) until an official vendor fix is available.
- Operational
Audit systems for file corruption resulting from symlink attacks, restore affected files from known-good backups, and monitor logs for signs of attempted or successful exploitation of userOsa.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0893?
CVE-1999-0893 is considered to have a moderate severity level due to its ability to allow local users to corrupt files.
How do I fix CVE-1999-0893?
To mitigate CVE-1999-0893, ensure that proper file permissions are set to restrict local user access to sensitive files.
Who is affected by CVE-1999-0893?
Local users of SCO OpenServer version 5.0 are affected by CVE-1999-0893.
What type of attack does CVE-1999-0893 describe?
CVE-1999-0893 describes a symlink attack that can be executed by local users to corrupt files.
Is there a patch available for CVE-1999-0893?
As of now, there is no specific patch mentioned for CVE-1999-0893, so it's essential to implement security best practices to mitigate the risk.