Vulnerability record · CVE-2001-0803 · published 6 December 2001
CVE-2001-0803: CDE dtspcd client connection buffer overflow allows remote command execution
Open Group · Cde Common Desktop Environment
The client connection routine in libDtSvc.so.1, part of the CDE Subprocess Control Service (dtspcd), contains a buffer overflow. A remote attacker can trigger it over the network and execute arbitrary commands. The flaw affects the Common Desktop Environment, a legacy Unix desktop stack still present on some older systems.
Description
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus very high EPSS, make this a top-priority legacy exposure.
What it is
The client connection routine in libDtSvc.so.1, part of the CDE Subprocess Control Service (dtspcd), contains a buffer overflow. A remote attacker can trigger it over the network and execute arbitrary commands. The flaw affects the Common Desktop Environment, a legacy Unix desktop stack still present on some older systems.
Impact
An unauthenticated remote attacker can run arbitrary commands with the privileges of the dtspcd process, typically root, leading to full host compromise. No user interaction or prior access is required.
Attack surface
Reachable over the network via the dtspcd service listening on TCP port 6112. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are needed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.85564, 99.7th percentile), and references include CERT/CC advisories and vendor patches, indicating broad historical attention.
What to do
- Apply vendor patches for CDE/dtspcd from the referenced advisories (Sun, SGI, Compaq, Caldera, CERT/CC).
- If dtspcd is not required, disable or remove the CDE Subprocess Control Service.
- Block TCP port 6112 at network boundaries and restrict access to trusted hosts only.
- Isolate or retire legacy systems running CDE that cannot be patched.
- Monitor for unexpected dtspcd process activity or child processes spawned by it.
Detection
- Monitor network traffic to TCP port 6112 for anomalous or oversized payloads.
- Audit dtspcd process trees for unexpected child processes or command execution.
- Check host logs for dtspcd crashes, restarts, or abnormal connection patterns.
- Use file integrity monitoring on libDtSvc.so.1 and related CDE binaries.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0803 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.