CVE-2012-2668 Information
Description
libraries/libldap/tls_m.c in OpenLDAP possibly 2.4.31 and earlier when using the Mozilla NSS backend always uses the default cipher suite even when TLSCipherSuite is set which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.
Reference
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309 http://rhn.redhat.com/errata/RHSA-2012-1151.html http://seclists.org/fulldisclosure/2019/Dec/26 http://security.gentoo.org/glsa/glsa-201406-36.xml http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commitdiff;h=2c2bb2e http://www.openldap.org/its/index.cgi?findid=7285 http://www.openwall.com/lists/oss-security/2012/06/05/4 http://www.openwall.com/lists/oss-security/2012/06/06/1 http://www.openwall.com/lists/oss-security/2012/06/06/2 http://www.securityfocus.com/bid/53823 http://www.securitytracker.com/id?1027127 https://bugzilla.redhat.com/show_bug.cgi?id=825875 https://exchange.xforce.ibmcloud.com/vulnerabilities/76099 https://seclists.org/bugtraq/2019/Dec/23 https://support.apple.com/kb/HT210788
Share on: