COMMAND

    vi

SYSTEMS AFFECTED

    Unixware 5.x (SCO_SV unixdev 3.2 5.0.5 i386)

PROBLEM

    Richard Johnson (Strategic  Reconnaissance Team Security  Advisory
    SRT2001-9) found  following.   vi makes  poor use  of /tmp.   File
    names are very predictable

    As a user

        ln -s /etc/passwd /tmp/Ex04161

    wait for root  to run vi  and viola when  he does he  will clobber
    /etc/passwd with a null file

SOLUTION

    Don't use vi or crontab -e until patched.