IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2012-08-08T10:00:00
Updated: 2024-08-06T19:26:09.007Z
Reserved: 2012-04-04T00:00:00
Link: CVE-2012-2191
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-08-08T10:26:18.767
Modified: 2024-11-21T01:38:40.743
Link: CVE-2012-2191
Redhat
No data.