The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg24027463 | patch |
http://osvdb.org/66782 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/60821 | vdb entry |
http://secunia.com/advisories/40791 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/42093 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IO12399 | patch vendor advisory |