CVE-1999-1571: Buffer Overflow
Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CVE-1999-1570.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SCO OpenServer/sarfrom your environment.Uninstall or remove the vulnerable 'sar' binary from SCO OpenServer systems if it is not required.
- Configuration
Prevent non-root users from executing the 'sar' binary — e.g., remove world/other execute permissions and remove the setuid bit if present so only root can run it.
SCO OpenServer sar executable_by_nonroot = disabled - Compensating control
Restrict local user access and privileges until the vulnerability is fixed — limit who can log in locally, restrict execution of system utilities to trusted administrators, and apply host-based access controls to prevent unprivileged users from running 'sar'.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1571?
CVE-1999-1571 is considered high severity due to the potential for local users to gain root privileges.
How do I fix CVE-1999-1571?
To fix CVE-1999-1571, upgrade to a version of SCO OpenServer that is not vulnerable, specifically beyond 5.0.5.
Who is affected by CVE-1999-1571?
CVE-1999-1571 affects local users of SCO OpenServer versions 5.0.0 to 5.0.5.
What is the nature of CVE-1999-1571?
CVE-1999-1571 is a buffer overflow vulnerability related to the sar command.
Can CVE-1999-1571 be exploited remotely?
CVE-1999-1571 cannot be exploited remotely, as it requires local access to the affected system.