CVE-1999-1302: High severity sco open desktop vulnerability

Published Nov 30, 1994
·
Updated

Unspecified vulnerability in ptchmod in SCO UNIX 4.2 and earlier allows local users to gain root access.

Affected Software

9 affected components
SCO Open Desktop=2.0
SCO Open Desktop=3.0
SCO Open Desktop Lite=3.0
SCO Openserver Enterprise System=3.0
SCO Openserver Network System=3.0
SCO UNIX<=4.2
SCO UNIX=3.2
SCO UNIX=4.0
SCO UNIX=4.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove the setuid bit or otherwise restrict execution of the pt_chmod binary so that unprivileged local users cannot execute it (make executable only by root or remove execute permission for non-root users).

    pt_chmod setuid bit = removed/disabled
  2. Compensating control

    Restrict local interactive and console access to trusted administrators only. Disable or remove unneeded local accounts, restrict shell access, and enforce physical/console access controls to prevent untrusted local users from accessing the system.

  3. Operational

    If exploitation is suspected, assume possible root compromise: preserve forensic data and logs, take affected systems offline, perform full rebuild from trusted media, and rotate all credentials, keys, and secrets used on the system.

Event History

Nov 30, 1994
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Sep 12, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1302?

CVE-1999-1302 is considered to be a critical vulnerability as it allows local users to gain root access.

2

How do I fix CVE-1999-1302?

To fix CVE-1999-1302, you should upgrade your SCO UNIX system to a version that is not vulnerable.

3

What versions of SCO software are affected by CVE-1999-1302?

CVE-1999-1302 affects SCO UNIX 4.2 and earlier versions, as well as various versions of SCO Open Desktop, OpenServer, and UNIX.

4

Who can exploit CVE-1999-1302?

CVE-1999-1302 can be exploited by any local user on the affected SCO UNIX systems.

5

Is there a workaround for CVE-1999-1302 if I can't upgrade?

There is no known effective workaround for CVE-1999-1302; upgrading is the only recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203