Vulnerability record · CVE-2001-0797 · published 12 December 2001
CVE-2001-0797: System V login buffer overflow via excessive arguments
Sgi · Irix
The login program on multiple System V based operating systems contains a buffer overflow that is triggered when a large number of arguments is passed to it. Because login is reachable through network services such as telnet and rlogin, this flaw exposes affected hosts to remote compromise. The record does not specify which login versions or builds are vulnerable.
Description
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityRemote, unauthenticated, full-impact buffer overflow in a core authentication binary across multiple major Unix platforms, with very high EPSS and an exploit-tagged reference.
What it is
The login program on multiple System V based operating systems contains a buffer overflow that is triggered when a large number of arguments is passed to it. Because login is reachable through network services such as telnet and rlogin, this flaw exposes affected hosts to remote compromise. The record does not specify which login versions or builds are vulnerable.
Impact
An attacker can execute arbitrary commands on the target host, and with the CVSS 2.0 vector showing complete confidentiality, integrity and availability impact, that likely means full control at the privilege level of the login process. No privilege escalation detail beyond this is given.
Attack surface
Reached remotely over the network through services that invoke login, such as telnet and rlogin, with no authentication required per the AV:N/AC:L/Au:N vector. No user interaction is indicated in the description.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.947 probability and 0.998 percentile, and one reference carries an Exploit tag. That combination suggests public exploit material exists and exploitation is plausible, though the record does not confirm active campaigns.
What to do
- Apply the vendor patches referenced in the SGI, Caldera/SCO, Sun, IBM and HP advisories, and the CERT/CC CA-2001-34 guidance.
- Disable or restrict telnet and rlogin on affected hosts, replacing them with SSH where possible.
- Block inbound telnet and rlogin at network boundaries and host firewalls until patching is complete.
- Monitor vendor support channels for updated patches, since the record does not enumerate fixed versions.
Detection
- Inspect authentication and service logs for telnet or rlogin sessions with unusually long or argument-heavy login invocations.
- Alert on login process crashes or core dumps on affected System V hosts.
- Hunt for unexpected child processes or command execution spawned from login on these systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0797 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0797), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.