IBM Security Directory Server < 6.1.0.61 / 6.2.0.36 / 6.3.0.30 / 6.3.1.2 with GSKit < 7.0.4.50 / 8.0.50.20 SSL CPU Utilization DoS

This script is Copyright (C) 2015 Tenable Network Security, Inc.


Synopsis :

The version of IBM Security Directory Server and GSKit is affected by
a denial of service vulnerability.

Description :

The remote host is running a version of IBM Security Directory Server
(formerly IBM Tivoli Directory Server) and a version of IBM Global
Security Kit (GSKit) that is affected by a denial of service
vulnerability due to a flaw in the GSKit library. An attacker can
exploit this issue via a specially-crafted SSL to use excessive CPU
resources resulting in the host to become unresponsive.

See also :

http://www-01.ibm.com/support/docview.wss?uid=swg21672724

Solution :

Install the appropriate fix based on the vendor's advisory :

- 6.1.0.61-ISS-ITDS
- 6.2.0.36-ISS-ITDS
- 6.3.0.30-ISS-ITDS
- 6.3.1.2-ISS-ISDS

Alternatively, upgrade GSKit to 7.0.4.50 or 8.0.50.20.

Risk factor :

High / CVSS Base Score : 7.1
(CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.2
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows

Nessus Plugin ID: 80482 ()

Bugtraq ID: 67238

CVE ID: CVE-2014-0963

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now