← Vulnerability feed

Vulnerability record · CVE-2001-0797 · published 12 December 2001

CVE-2001-0797: System V login buffer overflow via excessive arguments

Sgi · Irix

The login program on multiple System V based operating systems contains a buffer overflow that is triggered when a large number of arguments is passed to it. Because login is reachable through network services such as telnet and rlogin, this flaw exposes affected hosts to remote compromise. The record does not specify which login versions or builds are vulnerable.

10.0 CVSS 2.0 High EPSS 95% · top 0.1%
10.0CVSS 2.0 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
24References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityRemote, unauthenticated, full-impact buffer overflow in a core authentication binary across multiple major Unix platforms, with very high EPSS and an exploit-tagged reference.

What it is

The login program on multiple System V based operating systems contains a buffer overflow that is triggered when a large number of arguments is passed to it. Because login is reachable through network services such as telnet and rlogin, this flaw exposes affected hosts to remote compromise. The record does not specify which login versions or builds are vulnerable.

Impact

An attacker can execute arbitrary commands on the target host, and with the CVSS 2.0 vector showing complete confidentiality, integrity and availability impact, that likely means full control at the privilege level of the login process. No privilege escalation detail beyond this is given.

Attack surface

Reached remotely over the network through services that invoke login, such as telnet and rlogin, with no authentication required per the AV:N/AC:L/Au:N vector. No user interaction is indicated in the description.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.947 probability and 0.998 percentile, and one reference carries an Exploit tag. That combination suggests public exploit material exists and exploitation is plausible, though the record does not confirm active campaigns.

What to do

  • Apply the vendor patches referenced in the SGI, Caldera/SCO, Sun, IBM and HP advisories, and the CERT/CC CA-2001-34 guidance.
  • Disable or restrict telnet and rlogin on affected hosts, replacing them with SSH where possible.
  • Block inbound telnet and rlogin at network boundaries and host firewalls until patching is complete.
  • Monitor vendor support channels for updated patches, since the record does not enumerate fixed versions.

Detection

  • Inspect authentication and service logs for telnet or rlogin sessions with unusually long or argument-heavy login invocations.
  • Alert on login process crashes or core dumps on affected System V hosts.
  • Hunt for unexpected child processes or command execution spawned from login on these systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20011201-01-I
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.40/CSSA-2001-SCO.40.txt
http://marc.info/?l=bugtraq&m=100844757228307&w=2
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/213
http://www-1.ibm.com/support/search.wss?rs=0&q=IY26221&apar=only
http://www.cert.org/advisories/CA-2001-34.html PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/569272 US Government Resource
http://www.securityfocus.com/archive/1/246487 Vendor Advisory
http://www.securityfocus.com/bid/3681 ExploitPatchVendor Advisory
http://xforce.iss.net/alerts/advise105.php PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/7284
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2025
ftp://patches.sgi.com/support/free/security/advisories/20011201-01-I
ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.40/CSSA-2001-SCO.40.txt
http://marc.info/?l=bugtraq&m=100844757228307&w=2
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/213
http://www-1.ibm.com/support/search.wss?rs=0&q=IY26221&apar=only
http://www.cert.org/advisories/CA-2001-34.html PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/569272 US Government Resource
http://www.securityfocus.com/archive/1/246487 Vendor Advisory
http://www.securityfocus.com/bid/3681 ExploitPatchVendor Advisory
http://xforce.iss.net/alerts/advise105.php PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/7284
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2025

Track CVE-2001-0797 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed10.0CVE-2024-56346Ibm aix vulnerabilityIBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.EPSS 1.1%10.0CVE-2012-0131Hp distributed computing environment vulnerabilityDistributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly …EPSS 7.4%10.0CVE-2010-3187Ibm aix memory buffer overflow vulnerabilityBuffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.EPSS 20%10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2009-3699IBM AIX and VIOS rpc.cmsd XDR string stack buffer overflowA stack-based buffer overflow exists in libcsa.a, the calendar daemon library used by rpc.cmsd, in IBM AIX 5.x through 5.3.10, 6.x through 6.1.3, and…EPSS 62%analysed10.0CVE-2009-3517Ibm aix vulnerabilitynfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass…EPSS 4.4%10.0CVE-2009-2296Sun opensolaris vulnerabilityThe NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows r…EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2001-0797), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.