CVE
- Id
- 3952
- CVE No.
- CVE-2001-1148
- Status
- Candidate
- Description
- Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.
- Phase
- Modified (20050707)
- Votes
- ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese
- Comments
- Frech> XF:openserver-scoadmin-sysadm-bo(7281)