CVE-2000-0003: Buffer Overflow
Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Xinuos UnixWare/rtpmfrom your environment.Uninstall or remove the rtpm program if it is not required to eliminate the vulnerable binary.
- Configuration
Remove the setuid bit or otherwise revoke elevated execution privileges for the rtpm binary so local users cannot gain privileges via the vulnerable program.
Xinuos UnixWare rtpm setuid = disabled - Compensating control
Restrict which local accounts can execute the rtpm program (for example via filesystem permissions, sudoers rules, or local access controls) and reduce exposure of systems running rtpm to untrusted local users.
- Operational
If compromise is suspected, investigate for signs of privilege escalation, remediate any unauthorized changes, and rotate credentials that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0003?
CVE-2000-0003 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2000-0003?
To fix CVE-2000-0003, update your UnixWare software to the latest version provided by Xinuos.
Who is affected by CVE-2000-0003?
CVE-2000-0003 affects local users of the Xinuos UnixWare operating system.
What is the nature of the vulnerability described in CVE-2000-0003?
CVE-2000-0003 is a buffer overflow vulnerability that allows local users to gain heightened privileges.
Can CVE-2000-0003 be exploited remotely?
No, CVE-2000-0003 can only be exploited by local users with access to the affected system.