Vulnerability Name:

CVE-2003-0937 (CCN-13748)

Assigned:2003-11-11
Published:2003-11-11
Updated:2016-10-18
Summary:SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: SCO Security Advisory CSSA-2003-SCO.32
UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation.

Source: SCO
Type: Patch, Vendor Advisory
CSSA-2003-SCO.32

Source: MITRE
Type: CNA
CVE-2003-0937

Source: BUGTRAQ
Type: UNKNOWN
20031112 Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation.

Source: CCN
Type: OSVDB ID: 2818
Open UNIX/UnixWare procfs Privilege Escalation

Source: CCN
Type: Texonet Security Advisory 20031024 in SecurityFocus Archives
Insecure handling of procfs descriptors in UnixWare can lead to local

Source: CCN
Type: BID-9025
SCO UnixWare/Open UNIX Insecure Handling Of ProcFS Vulnerability

Source: MISC
Type: Patch, Vendor Advisory
http://www.texonet.com/advisories/TEXONET-20031024.txt

Source: XF
Type: UNKNOWN
unixware-procfs-gain-privileges(13748)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sco:open_unix:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:sco:unixware:7.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:sco:unixware:7.1.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sco open unix 8.0
    sco unixware 7.1.1
    sco unixware 7.1.3