Executive brief
A vulnerability exists in the security daemon of the OSF Distributed Computing Environment (DCE) used in older SGI IRIX operating systems. This component is responsible for managing security and authentication across a network of computers. An attacker can exploit this flaw to crash the security service, potentially disrupting user logins and network-wide security operations.
Technical details
A buffer overflow vulnerability exists in the OSF Distributed Computing Environment (DCE) security daemon (secd). The flaw is triggered when the daemon processes an excessively long string for a principal, group, or organization name. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the daemon, leading to a crash and a denial of service (DoS) condition. This issue primarily affects SGI IRIX version 6.4 and earlier. Patches were historically made available by SGI and The Open Group.
Affected products
- SGI IRIX 6.4 and earlier
- OSF Distributed Computing Environment (DCE) security daemon (secd)
Timeline
- 1997-10-24: disclosed
- 1997-10-24: advisory