Junglewise Threat Intelligence

CVE-1999-1131: SGI IRIX OSF DCE buffer overflow in secd

CVE-1999-1131 · Severity: medium · CVSS 5 · Published 1997-10-24

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability exists in the security daemon of the OSF Distributed Computing Environment (DCE) used in older SGI IRIX operating systems. This component is responsible for managing security and authentication across a network of computers. An attacker can exploit this flaw to crash the security service, potentially disrupting user logins and network-wide security operations.

Technical details

A buffer overflow vulnerability exists in the OSF Distributed Computing Environment (DCE) security daemon (secd). The flaw is triggered when the daemon processes an excessively long string for a principal, group, or organization name. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the daemon, leading to a crash and a denial of service (DoS) condition. This issue primarily affects SGI IRIX version 6.4 and earlier. Patches were historically made available by SGI and The Open Group.

Affected products

  • SGI IRIX 6.4 and earlier
  • OSF Distributed Computing Environment (DCE) security daemon (secd)

Timeline

  • 1997-10-24: disclosed
  • 1997-10-24: advisory

References

Related threats