CVE-2013-6747: Input Validation
IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6747?
CVE-2013-6747 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2013-6747?
To fix CVE-2013-6747, upgrade to IBM GSKit version 7.0.4.48 or 8.0.50.16 or higher.
Which software is affected by CVE-2013-6747?
CVE-2013-6747 affects IBM GSKit versions 7.x prior to 7.0.4.48 and 8.x prior to 8.0.50.16, and also impacts IBM Security Directory Server and Tivoli Directory Server.
What types of attacks can CVE-2013-6747 facilitate?
CVE-2013-6747 can facilitate remote denial of service attacks through malformed X.509 certificate chains.
Is there a workaround for CVE-2013-6747?
There are no known workarounds for CVE-2013-6747, thus upgrading is the recommended action.