Back

HIGH

openldap: incorrect multi-keyword mode cipherstring parsing

Published Dec 7, 2015

Description

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

Affected products

Remediation

Red Hat statement

This issue does not affect the version of openldap package as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of openldap package as shipped with Red Hat Enterprise Linux 8.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 7, 2015
Updated Aug 6, 2024
Reserved Apr 10, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 15, 2015