CVE-1999-0988: High severity SCO UnixWare vulnerability

Published Dec 4, 1999
·
Updated

UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

Affected Software

8 affected components
SCO UnixWare=2.0
SCO UnixWare=2.0.3
SCO UnixWare=2.1
SCO UnixWare=7.0
SCO UnixWare=7.0.1
SCO UnixWare=7.1
SCO UnixWare=7.1.1
SCO UnixWare=7.1.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove xinuos/unixware/pkgtrans from your environment.

    If pkgtrans is not required, uninstall the pkgtrans utility from affected systems to remove the attack surface.

  2. Configuration

    Change the pkgtrans binary ownership to root and remove execute permission for unprivileged users (e.g., set mode to disallow execution by others) and remove any setuid/setgid bits so local unprivileged users cannot run pkgtrans.

    UnixWare pkgtrans executable access / ownership / setuid = restrict execution to root/administrators; remove setuid/setgid if present
  3. Compensating control

    Until a vendor fix is available or pkgtrans is removed, restrict which local accounts can access systems with pkgtrans, tighten directory permissions on paths used by pkgtrans to prevent unprivileged users creating symlinks, and enable monitoring/alerting for unexpected symlink creation or pkgtrans invocations.

Event History

Dec 4, 1999
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0988?

CVE-1999-0988 is classified as a local privilege escalation vulnerability.

2

How do I fix CVE-1999-0988?

To fix CVE-1999-0988, users should upgrade to the latest patched version of UnixWare.

3

Who is affected by CVE-1999-0988?

CVE-1999-0988 affects local users on Xinuos UnixWare versions 2.0, 2.0.3, 2.1, 7.0, 7.0.1, 7.1, 7.1.1, and 7.1.16.

4

What type of attack leverages CVE-1999-0988?

CVE-1999-0988 can be exploited through a symlink attack.

5

Can remote users exploit CVE-1999-0988?

No, CVE-1999-0988 can only be exploited by local users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203