6
CVSSv2

CVE-2008-2943

Published: 30/06/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 up to and including 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulnerability," although there are likely scenarios in which a user is allowed to make administrative LDAP requests but does not have the privileges to stop the server.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli directory server 6.1.0.12

ibm tivoli directory server 6.1.0.13

ibm tivoli directory server 6.1.0.14

ibm tivoli directory server 6.1.0.7

ibm tivoli directory server 6.1.0.8

ibm tivoli directory server 6.1.0.0

ibm tivoli directory server 6.1.0.1

ibm tivoli directory server 6.1.0.3

ibm tivoli directory server 6.1.0.4

ibm tivoli directory server 6.1.0.15

ibm tivoli directory server 6.1.0.2

ibm tivoli directory server 6.1.0.9

ibm tivoli directory server 6.1.0.10

ibm tivoli directory server 6.1.0.11

ibm tivoli directory server 6.1.0.5

ibm tivoli directory server 6.1.0.6

Exploits

source: wwwsecurityfocuscom/bid/30010/info IBM Tivoli Directory Server is prone to a denial-of-service vulnerability because the server contains a double-free error An attacker can exploit this issue to crash the affected server with a SIGSEGV fault, denying service to legitimate users Tivoli Directory Server 6100 - 61015 are af ...