CVE-1999-1571
Description
Buffer overflow in SCO OpenServer sar -f parameter allows local users to gain root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Buffer overflow in SCO OpenServer sar -f parameter allows local users to gain root privileges.
Vulnerability
A buffer overflow exists in the sar utility on SCO OpenServer versions 5.0.0 through 5.0.5. The vulnerability is triggered by supplying an overly long argument to the -f parameter. This is distinct from another overflow in the -o parameter (CVE-1999-1570). Affected versions include all releases from 5.0.0 up to and including 5.0.5 [1].
Exploitation
An attacker must have local access to the system and be able to execute the sar binary, which is setuid root. By passing a specially crafted long string to the -f option, the attacker can overflow a buffer. For example, using a string of 2104 'A' characters causes a crash; 2105 characters triggers a segmentation fault and overwrites the instruction pointer with 0x41414141, indicating control of the return address [1].
Impact
Successful exploitation allows a local unprivileged user to execute arbitrary code with root privileges, because sar runs with setuid root. This results in complete compromise of the affected system [1][2].
Mitigation
SCO released an interim patch in the form of System Security Enhancement (SSE) package SSE037. The package provides replacement binaries for OpenServer versions 5.0.0 through 5.0.5 and was available for download from SCO's FTP server at ftp://ftp.sco.COM/SSE/sse037.tar.Z [2]. No workaround is documented; applying the patch is the recommended solution. The affected versions have long reached end-of-life, and no further updates are available.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:o:sco:openserver:5.0.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:sco:openserver:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:o:sco:openserver:5.0.5:*:*:*:*:*:*:*
- Range: 5.0.0 - 5.0.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- online.securityfocus.com/advisories/1843nvdPatchVendor Advisory
- www.iss.net/security_center/static/8989.phpnvdVendor Advisory
- stage.caldera.com/pub/security/sse/security_bulletins/SB-99.17cnvd
- stage.caldera.com/pub/security/sse/sse037c/sse037c.ltrnvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- online.securityfocus.com/archive/1/27074nvd
- www.securityfocus.com/bid/643nvd
News mentions
0No linked articles in our index yet.