VulnerabilityModified
CVE-1999-1295
Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.
MEDIUM 4.6EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.34% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- transarc/dce distributed file system
- Source
- cve@mitre.org
References
- http://www.cert.org/vendor_bulletins/VB-96.16.transarcPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7154
- http://www.cert.org/vendor_bulletins/VB-96.16.transarcPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7154
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.