Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2668

Опубликовано: 04 июн. 2012
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

Отчет

This issue did not affect the version of openldap as shipped with Red Hat Enterprise Linux 5, as it does not use the Mozilla NSS backend.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapNot affected
Red Hat Enterprise Linux 6openldapFixedRHSA-2012:115108.08.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=825875openldap: does not honor TLSCipherSuite settings

EPSS

Процентиль: 72%
0.00736
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

nvd
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

debian
около 13 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, wh ...

github
больше 3 лет назад

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

oracle-oval
около 13 лет назад

ELSA-2012-1151: openldap security and bug fix update (LOW)

EPSS

Процентиль: 72%
0.00736
Низкий

5 Medium

CVSS2