Description
SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.
Affected products
- sco / open_desktop1.0 – 1.0
- sco / open_desktop2.0 – 2.0
- sco / open_desktop3.0 – 3.0
- sco / open_desktop_lite3.0 – 3.0
- sco / openserver3.0 – 3.0
- sco / unixsystem_v386_3.2_operating_system – system_v386_3.2_operating_system
- sco / unixsystem_v386_3.2_operating_system_2.0 – system_v386_3.2_operating_system_2.0
- sco / unixsystem_v386_3.2_operating_system_4.0 – system_v386_3.2_operating_system_4.0
- sco / unixsystem_v386_3.2_operating_system_4.x – system_v386_3.2_operating_system_4.x