IBM Tivoli Directory Server < / / with GSKit < / X.509 Certificate Chain DoS

This script is Copyright (C) 2014-2017 Tenable Network Security, Inc.

Synopsis :

The version of IBM Tivoli Directory Server and GSKit is affected by
a denial of service vulnerability.

Description :

The remote host is running a version of IBM Tivoli Directory Server
6.1.0.x prior to, 6.2.0 prior to, or 6.3.0.x prior
to, and a version of IBM Global Security Kit (GSKit) 7.0.x
prior to or 8.0.50.x prior to It is, therefore,
affected by a denial of service vulnerability due to a flaw in the
GSKit library. An attacker can exploit this vulnerability via a
malformed X.509 certificate chain to cause an application crash or

See also :

Solution :

Install the appropriate fix based on the vendor's advisory :


Alternatively, upgrade GSKit to or

Risk factor :

High / CVSS Base Score : 7.1
CVSS Temporal Score : 6.2
Public Exploit Available : false

Family: Windows

Nessus Plugin ID: 72220 ()

Bugtraq ID: 65156

CVE ID: CVE-2013-6747

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now