← Vulnerability feed

Vulnerability record · CVE-2001-0803 · published 6 December 2001

CVE-2001-0803: CDE dtspcd client connection buffer overflow allows remote command execution

Open Group · Cde Common Desktop Environment

The client connection routine in libDtSvc.so.1, part of the CDE Subprocess Control Service (dtspcd), contains a buffer overflow. A remote attacker can trigger it over the network and execute arbitrary commands. The flaw affects the Common Desktop Environment, a legacy Unix desktop stack still present on some older systems.

10.0 CVSS 2.0 High EPSS 86% · top 0.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus very high EPSS, make this a top-priority legacy exposure.

What it is

The client connection routine in libDtSvc.so.1, part of the CDE Subprocess Control Service (dtspcd), contains a buffer overflow. A remote attacker can trigger it over the network and execute arbitrary commands. The flaw affects the Common Desktop Environment, a legacy Unix desktop stack still present on some older systems.

Impact

An unauthenticated remote attacker can run arbitrary commands with the privileges of the dtspcd process, typically root, leading to full host compromise. No user interaction or prior access is required.

Attack surface

Reachable over the network via the dtspcd service listening on TCP port 6112. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are needed.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.85564, 99.7th percentile), and references include CERT/CC advisories and vendor patches, indicating broad historical attention.

What to do

  • Apply vendor patches for CDE/dtspcd from the referenced advisories (Sun, SGI, Compaq, Caldera, CERT/CC).
  • If dtspcd is not required, disable or remove the CDE Subprocess Control Service.
  • Block TCP port 6112 at network boundaries and restrict access to trusted hosts only.
  • Isolate or retire legacy systems running CDE that cannot be patched.
  • Monitor for unexpected dtspcd process activity or child processes spawned by it.

Detection

  • Monitor network traffic to TCP port 6112 for anomalous or oversized payloads.
  • Audit dtspcd process trees for unexpected child processes or command execution.
  • Check host logs for dtspcd crashes, restarts, or abnormal connection patterns.
  • Use file integrity monitoring on libDtSvc.so.1 and related CDE binaries.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
http://www.cert.org/advisories/CA-2001-31.html US Government Resource
http://www.cert.org/advisories/CA-2002-01.html US Government Resource
http://www.kb.cert.org/vuls/id/172583 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/advisories/3651 PatchVendor Advisory
http://www.securityfocus.com/bid/3517 PatchVendor Advisory
http://xforce.iss.net/alerts/advise101.php Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/7396
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74
ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
http://www.cert.org/advisories/CA-2001-31.html US Government Resource
http://www.cert.org/advisories/CA-2002-01.html US Government Resource
http://www.kb.cert.org/vuls/id/172583 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/advisories/3651 PatchVendor Advisory
http://www.securityfocus.com/bid/3517 PatchVendor Advisory
http://xforce.iss.net/alerts/advise101.php Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/7396
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74

Track CVE-2001-0803 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0368Open group cde common desktop environment memory buffer overflow vulnerabilityDouble free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a cr…EPSS 11%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.8CVE-2026-20700Apple OS memory corruption allows arbitrary code executionA memory corruption flaw caused by improper state management affects iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Apple states it is aware of a re…KEVEPSS 1.3%analysed

Source: NIST National Vulnerability Database (record CVE-2001-0803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.