Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> General >> SCO OpenServer multiple vulnerabilities


Vulnerability Assessment Details

SCO OpenServer multiple vulnerabilities

Vulnerability Assessment Summary
Checks the remote SCO OpenServer

Detailed Explanation for this Vulnerability Assessment

OpenServer 5.0.7, OpenServer 5.0.6, and OpenServer 5.0.5 are vulnerable
to two (2) distinct exploits. Namely,

1) Xsco can be locally exploited by any valid user in order to escalate
their rights to 'root'. The bug is due to improper input handling
when running the command line switch '-co'.

2) There is a vulnerability in the MIT-SHM extension within
all X servers that are running as root. Any user with local X access
can exploit the MIT-SHM extension and gain read/write access to any
shared memory segment on the system.

*** This test relied on the banner of the remote system
*** to acertain that it is a SCO Unix server, so this alert
*** might be a false positive


More information can be found at:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0158
http://marc.theaimsgroup.com/?l=bugtraq&m=101776858410652&w=2
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0164
http://marc.theaimsgroup.com/?l=bugtraq&m=103547625009363&w=2
http://www.securityfocus.com/bid/4396

Solution: Install the patched binaries from
ftp://ftp.sco.com/pub/updates/OpenServer/CSSA-2003-SCO.26

Network Security Threat Level: High

Networks Security ID: 4396, 4985

Vulnerability Assessment Copyright: This script is Copyright (C) 2003 Tenable Network Security

Cables, Connectors


For Lenovo ideaPad Flex 5-14IIL05 5-14ARE 5-14ITL05 Palmrest Keyboard 5CB0Y85490 picture

For Lenovo ideaPad Flex 5-14IIL05 5-14ARE 5-14ITL05 Palmrest Keyboard 5CB0Y85490

$73.79



For Lenovo IdeaPad 1 15ADA7 15AMN7 LCD Back Cover Hinge Cover Bezel 5CB1F36621 picture

For Lenovo IdeaPad 1 15ADA7 15AMN7 LCD Back Cover Hinge Cover Bezel 5CB1F36621

$74.24



For Lenovo IdeaPad Gaming 3-15IHU6 15ACH6 Palmrest Keyboard Touchpad 5CB1D04600 picture

For Lenovo IdeaPad Gaming 3-15IHU6 15ACH6 Palmrest Keyboard Touchpad 5CB1D04600

$118.58



Lenovo Ideapad 1i 15.6

Lenovo Ideapad 1i 15.6" FHD Notebook Intel Core i5-1235U 8GB RAM 256GB SSD

$339.99



Lenovo IP 5 16IAU7 16

Lenovo IP 5 16IAU7 16" 2.5K Chromebook i3-1215U 8GB Ram 128GB eMMC Chrome OS

$219.99



Lenovo Loq 15Irh8 15

Lenovo Loq 15Irh8 15" Laptop Core i5-13420H GeForce RTX 2050 16GB 512GB SSD W11H

$519.99



Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 512GB SSD Windows 10 picture

Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 512GB SSD Windows 10

$261.24



Lenovo Legion Pro 5i 16

Lenovo Legion Pro 5i 16" Gaming Laptop RTX 4070 8GB i9-13900HX 16GB RAM 1TB SSD

$1399.99



Lenovo ThinkPad T495 - AMD Ryzen 3 PRO 3300U - 16GB RAM - 256GB SSD - Win10 Pro picture

Lenovo ThinkPad T495 - AMD Ryzen 3 PRO 3300U - 16GB RAM - 256GB SSD - Win10 Pro

$179.99



Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 256GB SSD Windows 10 picture

Lenovo ThinkPad L15 15.6” FHD Laptop AMD Ryzen 5 16GB RAM 256GB SSD Windows 10

$235.97



Discussions

No Discussions have been posted on this vulnerability.