First published: Wed Aug 08 2012(Updated: )
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Global Security Kit | <=8.0.13 | |
IBM Global Security Kit | =7.0.4.28 | |
IBM Global Security Kit | =7.0.4.29 | |
IBM Rational Directory Server | ||
IBM Tivoli Directory Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.