OSVDB ID: 84288

Title: SCO UnixWare shl Environment Handling Local Privilege Escalation

Info

Disclosure

Jul 20, 2012

Discovery

Dec 06, 1994

Dates

Exploit

Jul 20, 2012

Solution

Unknown

Description

SCO UnixWare contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error occurs in shl during the handling of certain environments. This may allow local attacker to gain escalated root privileges.

Classification

Location: Local Access Required
Attack Type: Other
Impact: Loss of Integrity
Solution: Workaround
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure
OSVDB: Authentication Required

Solution

Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: restrict privileges on shl.

Products

The SCO Group

UnixWare

Unspecified

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/84288