Lucene search

K
cveIbmCVE-2013-6747
HistoryJan 27, 2014 - 4:55 p.m.

CVE-2013-6747

2014-01-2716:55:04
CWE-20
ibm
web.nvd.nist.gov
52
ibm
gskit
denial of service
vulnerability
cve-2013-6747
isds
tds
x.509 certificate_chain

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

8.8

Confidence

High

EPSS

0.042

Percentile

92.2%

IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain.

Affected configurations

Nvd
Node
ibmglobal_security_kitMatch8.5
Node
ibmglobal_security_kitMatch7.0
OR
ibmglobal_security_kitMatch7.0.4.28
OR
ibmglobal_security_kitMatch7.0.4.29
OR
ibmglobal_security_kitMatch8.0
OR
ibmglobal_security_kitMatch8.0.13
OR
ibmsecurity_directory_serverMatch-
OR
ibmtivoli_directory_serverMatch-
VendorProductVersionCPE
ibmglobal_security_kit8.5cpe:2.3:a:ibm:global_security_kit:8.5:*:*:*:*:*:*:*
ibmglobal_security_kit7.0cpe:2.3:a:ibm:global_security_kit:7.0:*:*:*:*:*:*:*
ibmglobal_security_kit7.0.4.28cpe:2.3:a:ibm:global_security_kit:7.0.4.28:*:*:*:*:*:*:*
ibmglobal_security_kit7.0.4.29cpe:2.3:a:ibm:global_security_kit:7.0.4.29:*:*:*:*:*:*:*
ibmglobal_security_kit8.0cpe:2.3:a:ibm:global_security_kit:8.0:*:*:*:*:*:*:*
ibmglobal_security_kit8.0.13cpe:2.3:a:ibm:global_security_kit:8.0.13:*:*:*:*:*:*:*
ibmsecurity_directory_server-cpe:2.3:a:ibm:security_directory_server:-:*:*:*:*:*:*:*
ibmtivoli_directory_server-cpe:2.3:a:ibm:tivoli_directory_server:-:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

8.8

Confidence

High

EPSS

0.042

Percentile

92.2%