VYPR
Unrated severityNVD Advisory· Published Dec 30, 1999· Updated Apr 16, 2026

CVE-2000-0003

CVE-2000-0003

Description

Buffer overflow in UnixWare rtpm program allows local users to gain elevated privileges via a long environmental variable.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Buffer overflow in UnixWare rtpm program allows local users to gain elevated privileges via a long environmental variable.

Vulnerability

A buffer overflow vulnerability exists in the rtpm program shipped with UnixWare. The program fails to properly bounds-check an environmental variable before copying it into a fixed-size buffer. This allows a local attacker to overflow the buffer by supplying an overly long value for the affected variable. The vulnerability is present in versions of UnixWare prior to the patch released in January 2000 [1].

Exploitation

Exploitation requires local access to the system. The attacker sets the targeted environmental variable to a value exceeding the buffer capacity, then executes the rtpm program. The overflow corrupts adjacent memory, potentially overwriting the return address or other critical data. No authentication beyond a local user account is needed; the attacker must be able to run the rtpm binary.

Impact

Successful exploitation allows the attacker to execute arbitrary code with the privileges of the rtpm process. Since rtpm may run with elevated privileges (e.g., setuid root), this can result in full root compromise. The impact is local privilege escalation from a standard user account to superuser.

Mitigation

SCO released patches for this vulnerability in January 2000, available from the SCO security website [1]. Administrators should apply the appropriate patch for their UnixWare version. If patching is not possible, removing the setuid bit from the rtpm binary or restricting access to trusted users may reduce risk, but these are incomplete workarounds.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.