Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability

BID:8371

Info

Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability

Bugtraq ID: 8371
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Aug 08 2003 12:00AM
Updated: Aug 08 2003 12:00AM
Credit: This issue was announced by CERT.
Vulnerable: Open Group DCE 1.2.2 c - Domestic
Open Group DCE 1.2.2 c
IBM DCE 3.2 for Solaris
IBM DCE 3.2 for AIX
IBM DCE 3.1 for Solaris
IBM DCE 3.1 for AIX
IBM DCE 2.2 for Windows
HP VP Manager Windows A.06
HP OpenView VP Manager Solaris A.06
HP OpenView VP Manager HP-UX A.06
HP OpenView Performance Agent SUN-SOLARIS C.02.05
HP Openview Operations for Windows 7.0
HP OpenView Operations for UNIX 7.0
HP OpenView Operations for Solaris 7.0
HP IT/Operations
HP HP-UX 11.11
HP HP-UX 11.0
HP HP-UX 10.20
HP Advanced security for VP operations Solaris
HP Advanced security for VP operations HP-UX
Entegrity PC-DCE for Windows 5.0.1
Entegrity PC-DCE for Windows 4.0.8
Entegrity DCE/DFS for Tru64 Unix 4.3
Entegrity DCE/DFS for Tru64 Unix 4.2.2
Entegrity DCE/DFS for Tru64 Unix 4.2
Entegrity DCE/DFS for Tru64 Unix 4.1.6
Entegrity DCE/DFS for Tru64 Unix 4.1.5
Entegrity DCE/DFS for Tru64 Unix 4.1.4
Entegrity DCE/DFS for Linux 2.1
Cray UNICOS/mk 2.0.5 .54
Cray UNICOS/mk 1.5.1
Cray UNICOS/mk 1.5
Cray UNICOS MAX 1.3 .5
Cray UNICOS MAX 1.3
Cray UNICOS 9.2 .4
Cray UNICOS 9.2
Cray UNICOS 9.0.2 .5
Cray UNICOS 9.0
Cray UNICOS 8.3
Cray UNICOS 8.0
Cray UNICOS 7.0
Cray UNICOS 6.1
Cray UNICOS 6.0 E
Cray UNICOS 6.0
Compaq Tru64 5.1 a
Compaq Tru64 5.1
Compaq Tru64 5.0 a
Compaq OpenVMS 7.3 -1 Alpha
Compaq OpenVMS 7.3 VAX
Compaq OpenVMS 7.3 Alpha
Compaq OpenVMS 7.2.1 Alpha
Compaq OpenVMS 7.2 -2 Alpha
Compaq OpenVMS 7.2 -1H2 Alpha
Compaq OpenVMS 7.2 -1H1 Alpha
Compaq OpenVMS 7.2 VAX
Compaq OpenVMS 7.2 Alpha
Compaq OpenVMS 7.1 -2 Alpha
Compaq OpenVMS 7.1 VAX
Compaq OpenVMS 7.1 Alpha
Compaq OpenVMS 6.2 -1H3 Alpha
Compaq OpenVMS 6.2 -1H2 Alpha
Compaq OpenVMS 6.2 -1H1 Alpha
Compaq OpenVMS 6.2 VAX
Compaq OpenVMS 6.2 Alpha
Not Vulnerable:

Discussion

Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability

A vulnerability has been announced that may be exploited to cause a denial of services in multiple vendor OSF DCE (Distributed Computer Environment) implementations. Exploitation of this issue can deny availability of DCE services to legitimate clients.

It should be noted that some of the vendors reported side-effects of exploitation attempts for BID 8205 "Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability" may potentially trigger this issue in affected implementations. Scanning utilities for BID 8205 have also been reported to trigger this issue in some implementations.

Exploit / POC

Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability

Though there is no direct exploit available for this issue, exploits and scanning utilities for BID 8205 may trigger the issue.

Solution / Fix

Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability

Solution:
HP has released advisory HPSBUX0308-273 to address this issue. HP has also released advisories for Tru64 and OpenVMS which instruct users to apply the appropriate Entegrity fixes for OpenVMS/Tru64 systems running DCE.

HP has released a revised advisory (HPSBUX0308-274) and fixes to address this issue in OpenView Software implementations of DCE. See referenced advisory for further details regarding obtaining and applying fixes.

HP has released an advisory (HPSBUX0309-276) to address this issue in HP-UX 11.11 systems. Customers who are affected by this issue are advised to apply appropriate patches. Further information regarding obtaining and applying patches is available in the referenced advisory.

HP has relased advisory SSRT3608 to address this issue in OpenVMS.

Cray Inc. has acknowledged that Unicos systems may be affected and is tracking this issue via Spr 726429. Users should contact the vendor for further details about the status of this issue.

Entegrity has released a DCE Security Patch that can be applied to all support versions of affected software. Further information can be obtained on the Entegrity DCE Security Patch support page.

IBM has released DCE fixes for various platforms. Additionally, APAR IY47052 has been opened for the 3.2 release of DCE for AIX and Solaris.

HP has released advisory HPSBUX0308-273 to address this issue. HP has also released advisories for Tru64 and OpenVMS which instruct users to apply the appropriate Entegrity fixes for OpenVMS/Tru64 systems running DCE.

SGI has released patches to address this issue. Patch 5313 has been released which addresses this issue in DCE 1.2.2c and DCE 1.2.2c Domestic version. However, the domestic version requires the installation of an additional patch (5314) which is not publicly available. Information on obtaining patch 5314 can be obtained through the vendor.

HP has released an advisory (SSRT4741 rev.0) to address this issue. Please see the referenced advisory for more information. Users are advised to contact the vendor to obtain fixes.


Open Group DCE 1.2.2 c

Open Group DCE 1.2.2 c - Domestic

HP HP-UX 10.20

HP HP-UX 11.0

HP HP-UX 11.11

IBM DCE 2.2 for Windows

IBM DCE 3.1 for AIX

IBM DCE 3.1 for Solaris

IBM DCE 3.2 for Solaris

IBM DCE 3.2 for AIX

Compaq OpenVMS 6.2 -1H3 Alpha

Compaq OpenVMS 6.2 Alpha

Compaq OpenVMS 6.2 VAX

Compaq OpenVMS 6.2 -1H2 Alpha

Compaq OpenVMS 6.2 -1H1 Alpha

Compaq OpenVMS 7.1 VAX

Compaq OpenVMS 7.1 Alpha

Compaq OpenVMS 7.2 -2 Alpha

Compaq OpenVMS 7.2 Alpha

Compaq OpenVMS 7.2 VAX

Compaq OpenVMS 7.2 -1H1 Alpha

Compaq OpenVMS 7.2 -1H2 Alpha

Compaq OpenVMS 7.3 Alpha

Compaq OpenVMS 7.3 -1 Alpha

Compaq OpenVMS 7.3 VAX

References

Multiple Vendor OSF Distributed Computing Environment Denial Of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report