CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged users console session when the host is an NIS+ client, which allows others with physical access to login with any string.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Solaris | Sun | 2.6 (including) | 2.6 (including) |
| Sunos | Sun | - (including) | - (including) |
| Sunos | Sun | 5.6 (including) | 5.6 (including) |