VYPR
Unrated severityNVD Advisory· Published Nov 4, 1999· Updated Apr 16, 2026

CVE-1999-1571

CVE-1999-1571

Description

Buffer overflow in SCO OpenServer sar -f parameter allows local users to gain root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Buffer overflow in SCO OpenServer sar -f parameter allows local users to gain root privileges.

Vulnerability

A buffer overflow exists in the sar utility on SCO OpenServer versions 5.0.0 through 5.0.5. The vulnerability is triggered by supplying an overly long argument to the -f parameter. This is distinct from another overflow in the -o parameter (CVE-1999-1570). Affected versions include all releases from 5.0.0 up to and including 5.0.5 [1].

Exploitation

An attacker must have local access to the system and be able to execute the sar binary, which is setuid root. By passing a specially crafted long string to the -f option, the attacker can overflow a buffer. For example, using a string of 2104 'A' characters causes a crash; 2105 characters triggers a segmentation fault and overwrites the instruction pointer with 0x41414141, indicating control of the return address [1].

Impact

Successful exploitation allows a local unprivileged user to execute arbitrary code with root privileges, because sar runs with setuid root. This results in complete compromise of the affected system [1][2].

Mitigation

SCO released an interim patch in the form of System Security Enhancement (SSE) package SSE037. The package provides replacement binaries for OpenServer versions 5.0.0 through 5.0.5 and was available for download from SCO's FTP server at ftp://ftp.sco.COM/SSE/sse037.tar.Z [2]. No workaround is documented; applying the patch is the recommended solution. The affected versions have long reached end-of-life, and no further updates are available.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • cpe:2.3:o:sco:openserver:5.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:sco:openserver:5.0.0:*:*:*:*:*:*:*
    • cpe:2.3:o:sco:openserver:5.0.5:*:*:*:*:*:*:*
  • Range: 5.0.0 - 5.0.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.