CVE-2000-0099: Buffer Overflow
Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Xinuos UnixWare ppptalkfrom your environment.If ppptalk is not required, uninstall or remove the ppptalk binary from affected systems to eliminate the vulnerable component.
- Configuration
Restrict execution of the ppptalk binary to administrative/trusted accounts only by changing ownership and file permissions (for example: make root the owner and remove execute permission for non-admin users).
Xinuos UnixWare ppptalk execute_permission = restricted to administrative users - Compensating control
Limit which local accounts can log in or execute administrative commands on hosts with ppptalk present (use local ACLs, PAM restrictions, or host hardening) to reduce exposure to unprivileged local users.
- Operational
Monitor Xinuos vendor advisories for a supplied patch or fixed version for the ppptalk vulnerability and apply the vendor-provided fix as soon as it becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0099?
The severity of CVE-2000-0099 is considered high due to the potential for local privilege escalation.
How do I fix CVE-2000-0099?
To fix CVE-2000-0099, users should upgrade to a patched version of Xinuos UnixWare that addresses the buffer overflow vulnerability.
Who is affected by CVE-2000-0099?
CVE-2000-0099 affects local users of Xinuos UnixWare versions 7.0.0, 7.0.1, and 7.1.0.
What causes CVE-2000-0099?
CVE-2000-0099 is caused by a buffer overflow in the ppptalk command when processing a long prompt argument.
What are the implications of CVE-2000-0099?
The implications of CVE-2000-0099 include the risk of unauthorized privilege escalation for local users.