Vulnerability Name: | CVE-2003-0937 (CCN-13748) | ||||||||
Assigned: | 2003-11-11 | ||||||||
Published: | 2003-11-11 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: SCO Security Advisory CSSA-2003-SCO.32 UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation. Source: SCO Type: Patch, Vendor Advisory CSSA-2003-SCO.32 Source: MITRE Type: CNA CVE-2003-0937 Source: BUGTRAQ Type: UNKNOWN 20031112 Insecure handling of procfs descriptors in UnixWare can lead to local privilege escalation. Source: CCN Type: OSVDB ID: 2818 Open UNIX/UnixWare procfs Privilege Escalation Source: CCN Type: Texonet Security Advisory 20031024 in SecurityFocus Archives Insecure handling of procfs descriptors in UnixWare can lead to local Source: CCN Type: BID-9025 SCO UnixWare/Open UNIX Insecure Handling Of ProcFS Vulnerability Source: MISC Type: Patch, Vendor Advisory http://www.texonet.com/advisories/TEXONET-20031024.txt Source: XF Type: UNKNOWN unixware-procfs-gain-privileges(13748) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |