CVE-2008-7289 Information

Description

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.

Reference

http://www.ibm.com/support/docview.wss?uid=swg1IO09667 http://www.ibm.com/support/docview.wss?uid=swg24029663

Share on: