IBM Tivoli Directory Server 6.1 < 6.1.0.59 / 6.2 < 6.2.0.34 / 6.3 < 6.3.0.26 Denial of Service

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The version of IBM Tivoli Directory Server is affected by a denial of
service vulnerability.

Description :

The remote Windows host is running a Version of IBM Tivoli Server
Directory prior to 6.1.0.59 / 6.2.0.34 / 6.3.0.26 and a version of
GSKit prior to 7.0.4.48 / 8.0.50.16. It is, therefore, affected by a
denial of service vulnerability due to a flaw in the GSKit component.
An attacker can exploit this vulnerability via a malformed X.509
certificate chain to cause an application crash or hang.

See also :

http://www.nessus.org/u?1afae799
http://www.nessus.org/u?9c119340

Solution :

Install the appropriate fix based on the vendor's advisory :

- 6.1.0.59-ISS-ITDFS-IF0059
- 6.2.0.34-ISS-ITDFS-IF0034
- 6.3.0.26-ISS-ITDFS-IF0026

Alternatively, upgrade GSKit to 7.0.4.48 or 8.0.50.16.

Risk factor :

High / CVSS Base Score : 7.1
(CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.2
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows

Nessus Plugin ID: 72220 ()

Bugtraq ID: 65156

CVE ID: CVE-2013-6747