vendor:
Unixware
by:
prdelka
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Unixware
Affected Version From: 7.1.2003
Affected Version To: 7.1.2003
Patch Exists: NO
Related CWE: N/A
CPE: o:sco:unixware:7.1.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: SCO UNIX_SVR5
2002
SCO Unixware 7.1.3 ptrace local root exploit
SCO Unixware 7.1.3 kernel allows unprivileged users to debug binaries. The condition can be exploited by an attacker when he has execute permissions to a file which has the suid bit set. An attacker can use a shellcode to gain root access.
Mitigation:
Ensure that all SUID binaries are properly secured and that users are not allowed to debug them.