Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3276

Опубликовано: 15 июл. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

A flaw was found in the way OpenLDAP parsed OpenSSL-style cipher strings. As a result, OpenLDAP could potentially use ciphers that were not intended to be enabled.

Отчет

This issue does not affect the version of openldap package as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of openldap package as shipped with Red Hat Enterprise Linux 8.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapNot affected
Red Hat Enterprise Linux 6openldapWill not fix
Red Hat Enterprise Linux 7openldapFixedRHSA-2015:213119.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-682
https://bugzilla.redhat.com/show_bug.cgi?id=1238322openldap: incorrect multi-keyword mode cipherstring parsing

EPSS

Процентиль: 82%
0.01757
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

CVSS3: 7.5
nvd
больше 9 лет назад

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

CVSS3: 7.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 9 лет назад

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDA ...

CVSS3: 7.5
github
около 3 лет назад

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

EPSS

Процентиль: 82%
0.01757
Низкий

4.3 Medium

CVSS2