vendor:
UnixWare
by:
qaaz
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: UnixWare
Affected Version From: SCO UnixWare < 7.1.4 p534589
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: UnixWare
2008
UnixWare pkgadd Local Root Exploit
This exploit is for SCO UnixWare < 7.1.4 p534589. It uses the pkgadd command to create a symbolic link to /etc/default/su, which is then used to gain root privileges.
Mitigation:
Upgrade to the latest version of SCO UnixWare