CVE-2012-2191: Input Validation
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2191?
CVE-2012-2191 is classified as a medium severity vulnerability.
How do I fix CVE-2012-2191?
To fix CVE-2012-2191, upgrade IBM Global Security Kit to version 8.0.14.22 or later.
What systems are affected by CVE-2012-2191?
CVE-2012-2191 affects IBM Global Security Kit versions prior to 8.0.14.22, IBM Rational Directory Server, and IBM Tivoli Directory Server.
What type of attack does CVE-2012-2191 help facilitate?
CVE-2012-2191 facilitates a timing attack against the SSL CBC protection mechanism.
Who can exploit CVE-2012-2191?
Remote attackers can exploit CVE-2012-2191 due to improper validation of data during execution.