search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Multiple Open Software Foundation Distributed Computing Environment (DCE) implementations vulnerable to DoS

Vulnerability Note VU#377804

Original Release Date: 2003-08-08 | Last Revised: 2003-08-18

Overview

A denial-of-service vulnerability exists in multiple vendor implementations of the Distributed Computing Environment. This vulnerability may allow a remote attacker to cause the service to fail. Note that this vulnerability may be triggered by attackers attempting to exploit VU#568148 and VU#326746.

Description

The Open Group describes the Distributed Computing Environment (DCE) as an "industry-standard, vendor-neutral set of distributed computing technologies." They go on to describe DCE as follows:

DCE provides a complete Distributed Computing Environment infrastructure. It provides security services to protect and control access to data, name services that make it easy to find distributed resources, and a highly scalable model for organizing widely scattered users, services, and data. DCE runs on all major computing platforms and is designed to support distributed applications in heterogeneous hardware and software environments.
A vulnerability has been discovered in DCE which may allow a remote attacker to cause the DCE service to either hang or terminate, which will effectively make it impossible for DCE clients to communicate with the DCE server.

Impact

A remote attacker may be able to cause the DCE service to either hang or terminate, which will effectively make it impossible for DCE clients to communicate with the DCE server.

Solution

Apply a patch.

Vendor Information

377804
 

View all 56 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This document was written by Ian A Finlay.

Other Information

CVE IDs: None
Severity Metric: 22.78
Date Public: 2003-08-07
Date First Published: 2003-08-08
Date Last Updated: 2003-08-18 14:12 UTC
Document Revision: 18

Sponsored by CISA.