CVE-1999-1131: Buffer Overflow
Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SGI IRIX OSF DCE (secd)from your environment.Uninstall the OSF Distributed Computing Environment security daemon (secd) or remove DCE packages from affected systems if DCE functionality is not required.
- Configuration
Stop and disable the secd service on affected IRIX systems if DCE security services are not required.
OSF Distributed Computing Environment (DCE) secd (security daemon) service_enabled / running = disabled / stopped - Compensating control
Restrict network access to DCE/secd services using perimeter and host-based firewalls or ACLs; permit only trusted management hosts to reach secd to reduce exposure until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1131?
CVE-1999-1131 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-1999-1131?
To fix CVE-1999-1131, upgrade to a version of SGI IRIX that is not affected, such as versions later than 6.4.
Which SGI IRIX versions are affected by CVE-1999-1131?
CVE-1999-1131 affects SGI IRIX versions 5.3, 6.2, 6.3, and 6.4.
What kind of attack can exploit CVE-1999-1131?
CVE-1999-1131 can be exploited by attackers sending overly long principal, group, or organization names to cause a buffer overflow.
Is CVE-1999-1131 still a threat today?
While CVE-1999-1131 was relevant for older IRIX systems, it presents a lower risk today due to the discontinuation of those versions.