Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g25q-m772-8jx8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

EPSS

Процентиль: 72%
0.00736
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

redhat
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

nvd
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

debian
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, wh ...

oracle-oval
около 13 лет назад

ELSA-2012-1151: openldap security and bug fix update (LOW)

EPSS

Процентиль: 72%
0.00736
Низкий

Дефекты

CWE-200