CVE-2001-1148: Buffer Overflow
Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1148?
CVE-2001-1148 is considered high severity due to the potential for local users to gain elevated privileges.
How do I fix CVE-2001-1148?
To mitigate CVE-2001-1148, upgrade to a version of SCO OpenServer later than 5.0.6a which addresses the buffer overflow vulnerabilities.
Which programs are affected by CVE-2001-1148?
CVE-2001-1148 affects programs such as atcronsh, auditsh, authsh, backupsh, lpsh, sysadm.menu, and termsh used by scoadmin and sysadmsh.
Can CVE-2001-1148 be exploited remotely?
CVE-2001-1148 is not a remote exploit; it requires local access for exploitation.
What systems are vulnerable to CVE-2001-1148?
CVE-2001-1148 affects SCO OpenServer versions up to and including 5.0.6a.