CVE-2012-2668Sensitive Information Exposure in Openldap

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 17

Description

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

🔴Vulnerability Details

1
GHSA
GHSA-g25q-m772-8jx8: libraries/libldap/tls_m2022-05-17

📋Vendor Advisories

3
Apple
CVE-2012-2668: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra2019-12-10
Red Hat
openldap: does not honor TLSCipherSuite settings2012-06-04
Debian
CVE-2012-2668: openldap - libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using t...2012

💬Community

2
Bugzilla
CVE-2012-2668 CVE-2012-1164 openldap various flaws [fedora-all]2012-06-06
Bugzilla
CVE-2012-2668 openldap: does not honor TLSCipherSuite settings2012-05-28