VulnerabilityModified
CVE-1999-1041
Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.
HIGH 7.2EPSS 1.05%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- sco/openserver · sco/unix
- Source
- cve@mitre.org
References
- ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a
- http://marc.info/?l=bugtraq&m=90686250717719&w=2
- http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreenPatch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/10420Vendor Advisory
- ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a
- http://marc.info/?l=bugtraq&m=90686250717719&w=2
- http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreenPatch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/10420Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.