IBM GSKit SSL Handshake Unspecified Denial of Service Vulnerability
BID:10475
Info
IBM GSKit SSL Handshake Unspecified Denial of Service Vulnerability
| Bugtraq ID: | 10475 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2004 12:00AM |
| Updated: | Jun 07 2004 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
IBM WebSphere MQ 5.3 .0.5 IBM WebSphere MQ 5.3 .0.1 IBM WebSphere MQ 5.3 IBM Tivoli Access Manager for e-business 5.1 IBM Tivoli Access Manager for e-business 4.1 IBM Tivoli Access Manager for e-business 3.9 IBM Tivoli Access Manager for Business Integration 5.1 IBM Lotus Sametime 3.1 IBM Lotus Sametime 3.0 a IBM Lotus Sametime 3.0 IBM Lotus Instant Messaging and Web Conferencing 6.5.1 IBM Lotus Instant Messaging and Web Conferencing 6.5 IBM HTTP Server 2.0.47 IBM HTTP Server 2.0.42 .2 IBM HTTP Server 2.0.42 IBM HTTP Server 1.3.28 IBM HTTP Server 1.3.26 .2 IBM HTTP Server 1.3.26 .1 IBM HTTP Server 1.3.26 IBM HTTP Server 1.3.19 .5 IBM HTTP Server 1.3.19 .4 IBM HTTP Server 1.3.19 .3 IBM HTTP Server 1.3.19 .2 IBM HTTP Server 1.3.19 .1 IBM HTTP Server 1.3.19 IBM HTTP Server 1.3.12 .7 IBM HTTP Server 1.3.12 .6 IBM HTTP Server 1.3.12 .5 IBM HTTP Server 1.3.12 .4 IBM HTTP Server 1.3.12 .3 IBM HTTP Server 1.3.12 .2 IBM HTTP Server 1.3.12 .1 IBM HTTP Server 1.3.12 IBM Directory Server 5.1 IBM Directory Server 4.1 |
| Not Vulnerable: | |
Discussion
IBM GSKit SSL Handshake Unspecified Denial of Service Vulnerability
IBM Global Security Toolkit (GSKit) is susceptible to an unspecified denial of service vulnerability.
IBM has reported that during SSL handshakes, malformed packets can either crash the affected application, or cause a performance degradation.
Multiple applications incorporate GSKit, and are therefore all affected by this vulnerability.
IBM Global Security Toolkit (GSKit) is susceptible to an unspecified denial of service vulnerability.
IBM has reported that during SSL handshakes, malformed packets can either crash the affected application, or cause a performance degradation.
Multiple applications incorporate GSKit, and are therefore all affected by this vulnerability.
Exploit / POC
IBM GSKit SSL Handshake Unspecified Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM GSKit SSL Handshake Unspecified Denial of Service Vulnerability
Solution:
IBM has released fixes for affected applications, please see the referenced web site for a matrix of fixes and locations to download updates.
Some fixes require contacting IBM support, please see the referenced web site for further information.
Solution:
IBM has released fixes for affected applications, please see the referenced web site for a matrix of fixes and locations to download updates.
Some fixes require contacting IBM support, please see the referenced web site for further information.
References
IBM GSKit SSL Handshake Unspecified Denial of Service Vulnerability
References:
References: