IBM Tivoli Directory Server < 6.1.0.59 / 6.2.0.34 / 6.3.0.26 with GSKit < 7.0.4.48 / 8.0.50.16 X.509 Certificate Chain DoS

high Nessus Plugin ID 72220

Synopsis

The version of IBM Tivoli Directory Server and GSKit is affected by a denial of service vulnerability.

Description

The remote host is running a version of IBM Tivoli Directory Server 6.1.0.x prior to 6.1.0.59, 6.2.0 prior to 6.2.0.34, or 6.3.0.x prior to 6.3.0.26, and a version of IBM Global Security Kit (GSKit) 7.0.x prior to 7.0.4.48 or 8.0.50.x prior to 8.0.50.16. It is, therefore, affected by a denial of service vulnerability due to a flaw in the GSKit library. An attacker can exploit this vulnerability via a malformed X.509 certificate chain to cause an application crash or hang.

Solution

Install the appropriate fix based on the vendor's advisory :

- 6.1.0.59-ISS-ITDFS-IF0059
- 6.2.0.34-ISS-ITDFS-IF0034
- 6.3.0.26-ISS-ITDFS-IF0026

Alternatively, upgrade GSKit to 7.0.4.48 or 8.0.50.16.

See Also

http://www.nessus.org/u?1afae799

http://www.nessus.org/u?93389b8b

Plugin Details

Severity: High

ID: 72220

File Name: ibm_gskit_swg21662902.nasl

Version: 1.7

Type: local

Agent: windows

Family: Windows

Published: 1/29/2014

Updated: 7/12/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Information

CPE: cpe:/a:ibm:tivoli_directory_server

Required KB Items: installed_sw/IBM GSKit, installed_sw/IBM Security Directory Server

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2014

Vulnerability Publication Date: 1/24/2014

Reference Information

CVE: CVE-2013-6747

BID: 65156