CVE-2013-6747

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/01/2014
Last modified:
11/04/2025

Description

IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:global_security_kit:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:global_security_kit:7.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:global_security_kit:7.0.4.28:*:*:*:*:*:*:*
cpe:2.3:a:ibm:global_security_kit:7.0.4.29:*:*:*:*:*:*:*
cpe:2.3:a:ibm:global_security_kit:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:global_security_kit:8.0.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_directory_server:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_directory_server:-:*:*:*:*:*:*:*