CVE-2000-0370: Critical severity Caldera OpenLinux vulnerability
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Caldera Linux smailfrom your environment.Uninstall Caldera Linux smail if it is not required.
- Configuration
Disable the smail debug option and ensure rmail is not invoked with the -D option to prevent interpretation of shell metacharacters.
Caldera Linux smail debug option (-D) for rmail = disabled / do not use -D - Compensating control
Restrict remote access to the rmail/smail service (for example, firewall rules or access controls) to trusted hosts only to mitigate remote exploitation of the -D debug option.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0370?
CVE-2000-0370 is classified as a high-severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2000-0370?
To fix CVE-2000-0370, it is recommended to disable the debug option in smail or upgrade to a version of Caldera Linux that is not affected by this vulnerability.
Which versions of SCO OpenLinux are affected by CVE-2000-0370?
CVE-2000-0370 affects SCO OpenLinux versions 1.0, 1.1, 1.2, and 1.3.
Can CVE-2000-0370 be exploited remotely?
Yes, CVE-2000-0370 can be exploited remotely by attackers using shell metacharacters in the rmail command's -D option.
What type of attack is possible with CVE-2000-0370?
CVE-2000-0370 allows remote attackers to execute arbitrary commands on the affected systems.