IBM Tivoli Directory Server < / / with GSKit < / X.509 Certificate Chain DoS

High Nessus Plugin ID 72220


The version of IBM Tivoli Directory Server and GSKit is affected by a denial of service vulnerability.


The remote host is running a version of IBM Tivoli Directory Server 6.1.0.x prior to, 6.2.0 prior to, or 6.3.0.x prior to, and a version of IBM Global Security Kit (GSKit) 7.0.x prior to or 8.0.50.x prior to It is, therefore, affected by a denial of service vulnerability due to a flaw in the GSKit library. An attacker can exploit this vulnerability via a malformed X.509 certificate chain to cause an application crash or hang.


Install the appropriate fix based on the vendor's advisory :


Alternatively, upgrade GSKit to or

See Also

Plugin Details

Severity: High

ID: 72220

File Name: ibm_gskit_swg21662902.nasl

Version: $Revision: 1.6 $

Type: local

Agent: windows

Family: Windows

Published: 2014/01/29

Modified: 2017/07/05

Dependencies: 67230, 58813

Risk Information

Risk Factor: High


Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:tivoli_directory_server

Required KB Items: installed_sw/IBM GSKit, installed_sw/IBM Security Directory Server

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/01/14

Vulnerability Publication Date: 2014/01/24

Reference Information

CVE: CVE-2013-6747

BID: 65156

OSVDB: 102556