CVE-2003-1021: High severity SCO OpenServer vulnerability
Published Jan 26, 2005
·Updated
The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.
Affected Software
18 affected components
SCO OpenServer=5.0
SCO OpenServer=5.0.1
SCO OpenServer=5.0.2
SCO OpenServer=5.0.3
SCO OpenServer=5.0.4
SCO OpenServer=5.0.5
SCO OpenServer=5.0.6
SCO OpenServer=5.0.6a
SCO OpenServer=5.0.7
SCO OpenServer=5.0
SCO OpenServer=5.0.2
SCO OpenServer=5.0.7
SCO OpenServer=5.0.5
SCO OpenServer=5.0.3
SCO OpenServer=5.0.6a
SCO OpenServer=5.0.1
SCO OpenServer=5.0.6
SCO OpenServer=5.0.4
Remediation
Patch Available
Patch Available
Event History
Jan 26, 2005
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1021?
CVE-2003-1021 is classified as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2003-1021?
To mitigate CVE-2003-1021, upgrade OpenServer to a version that is not affected, such as any version later than 5.0.7.
3
Who is affected by CVE-2003-1021?
Local users of Xinuos OpenServer versions 5.0.6 and 5.0.7 are affected by CVE-2003-1021.
4
What causes CVE-2003-1021?
CVE-2003-1021 is caused by the scosession program allowing local users to gain elevated privileges through crafted command line strings.
5
Are there any known exploits for CVE-2003-1021?
Yes, there are exploited cases reported that demonstrate how an attacker can utilize this vulnerability to escalate privileges.