CVE-1999-1041: Buffer Overflow

Published Aug 27, 1998
·
Updated

Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.

Affected Software

2 affected components
SCO OpenServer=5.0
SCO UNIX=3.2v4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove mscreen (SCO OpenServer / SCO UNIX) from your environment.

    Uninstall mscreen from affected systems (SCO OpenServer 5.0 and SCO UNIX 3.2v4) if the utility is not required.

  2. Configuration

    Remove execute permission for non-privileged users (for example, via filesystem permissions or ACLs) so only trusted administrators can run mscreen, preventing local users from triggering the buffer overflow via a long TERM environment variable or a long .mscreenrc entry.

    mscreen execute_permission = remove for non-privileged users
  3. Compensating control

    Restrict who can run or interact with mscreen and who can create or modify .mscreenrc files (use filesystem permissions, ACLs, or local account restrictions) to mitigate exploitation via long TERM environment variables or long .mscreenrc entries.

  4. Operational

    If exploitation is suspected, investigate for signs of local privilege escalation, restore affected systems from known-good backups or rebuild as needed, and rotate any credentials or keys that may have been exposed before re-enabling mscreen.

Event History

Aug 27, 1998
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1041?

CVE-1999-1041 is considered to have high severity due to its potential for local users to gain root access.

2

How do I fix CVE-1999-1041?

To fix CVE-1999-1041, ensure that the mscreen program is updated to a non-vulnerable version and restrict access to the system.

3

Who is affected by CVE-1999-1041?

CVE-1999-1041 affects users of SCO OpenServer 5.0 and SCO UNIX 3.2v4.

4

What causes CVE-1999-1041?

CVE-1999-1041 is caused by a buffer overflow vulnerability triggered by overly long input in the TERM environment variable and .mscreenrc file.

5

Can CVE-1999-1041 be exploited remotely?

CVE-1999-1041 cannot be exploited remotely as it requires local access to the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203