Do your applications use this vulnerable package?
Test your applications
Overview
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
References
CVSS Score
5.3
medium severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityLow
-
AvailabilityNone
- CVE
- CVE-2015-3276
- CWE
- CWE-310
- Snyk ID
- SNYK-DEBIAN8-OPENLDAP-304652
- Disclosed
- 07 Dec, 2015
- Published
- 07 Dec, 2015