PT-1996-1061 · Transarc+1 · Transarc Dce Distributed File System+1

Published

1996-09-17

·

Updated

2017-12-19

·

CVE-1999-1295

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Transarc DCE Distributed File System (DFS) version 1.1 for Solaris 2.4 and 2.5
Description The issue arises from the improper initialization of the grouplist for users who are part of a large number of groups. This could potentially allow such users to access resources protected by DFS that they should not have access to.
Recommendations For Transarc DCE Distributed File System (DFS) version 1.1 on Solaris 2.4 and 2.5, consider restricting access to sensitive resources until a proper fix is applied to ensure grouplist initialization is handled correctly for users with multiple group memberships. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1295

Affected Products

Solaris
Transarc Dce Distributed File System