Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2012-1151

Опубликовано: 08 авг. 2012
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2012-1151: openldap security and bug fix update (LOW)

[2.4.23-26.2]

  • CVE-2012-2668 (#825875) cipher suite selection by name can be ignored default cipher suite is always selected

[2.4.23-26.1]

  • fix: smbk5pwd module computes invalid LM hashes (#820278)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

openldap

2.4.23-26.el6_3.2

openldap-clients

2.4.23-26.el6_3.2

openldap-devel

2.4.23-26.el6_3.2

openldap-servers

2.4.23-26.el6_3.2

openldap-servers-sql

2.4.23-26.el6_3.2

Oracle Linux i686

openldap

2.4.23-26.el6_3.2

openldap-clients

2.4.23-26.el6_3.2

openldap-devel

2.4.23-26.el6_3.2

openldap-servers

2.4.23-26.el6_3.2

openldap-servers-sql

2.4.23-26.el6_3.2

Связанные CVE

Связанные уязвимости

ubuntu
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

redhat
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

nvd
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

debian
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, wh ...

github
больше 3 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.