CVE-1999-1302: High severity sco open desktop vulnerability
Unspecified vulnerability in ptchmod in SCO UNIX 4.2 and earlier allows local users to gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the setuid bit or otherwise restrict execution of the pt_chmod binary so that unprivileged local users cannot execute it (make executable only by root or remove execute permission for non-root users).
pt_chmod setuid bit = removed/disabled - Compensating control
Restrict local interactive and console access to trusted administrators only. Disable or remove unneeded local accounts, restrict shell access, and enforce physical/console access controls to prevent untrusted local users from accessing the system.
- Operational
If exploitation is suspected, assume possible root compromise: preserve forensic data and logs, take affected systems offline, perform full rebuild from trusted media, and rotate all credentials, keys, and secrets used on the system.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1302?
CVE-1999-1302 is considered to be a critical vulnerability as it allows local users to gain root access.
How do I fix CVE-1999-1302?
To fix CVE-1999-1302, you should upgrade your SCO UNIX system to a version that is not vulnerable.
What versions of SCO software are affected by CVE-1999-1302?
CVE-1999-1302 affects SCO UNIX 4.2 and earlier versions, as well as various versions of SCO Open Desktop, OpenServer, and UNIX.
Who can exploit CVE-1999-1302?
CVE-1999-1302 can be exploited by any local user on the affected SCO UNIX systems.
Is there a workaround for CVE-1999-1302 if I can't upgrade?
There is no known effective workaround for CVE-1999-1302; upgrading is the only recommended solution.