CVE-2015-3230
published 2015-10-29CVE-2015-3230: 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.57%
83.5th percentile
389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.3.12-1 (bookworm) | 389-ds-base 1.3.3.12-1 (bookworm) |
| fedoraproject | 389_directory_server | <= 1.3.3.10 | — |
| port389 | 389-ds-base | >= 0 < 1.3.3.12-1 | 1.3.3.12-1 |
| port389 | 389-ds-base | >= 0 < 1.3.3.12-1 | 1.3.3.12-1 |
| port389 | 389-ds-base | >= 0 < 1.3.3.12-1 | 1.3.3.12-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)
vendor_redhat·2015-06-09·CVSS 7.5
CVE-2015-3230 [HIGH] CWE-665 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)
389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)
389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.
Statement: This issue was correct in Red Hat Enterprise Linux 7 via RHBA-2015:1554. It did not affect the versions of 389-ds-base as shipped with Red Hat Enterprise Linux 6.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2015-3230: 389-ds-base - 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not...
vendor_debian·2015·CVSS 7.5
CVE-2015-3230 [HIGH] CVE-2015-3230: 389-ds-base - 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not...
389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.
Scope: local
bookworm: resolved (fixed in 1.3.3.12-1)
bullseye: resolved (fixed in 1.3.3.12-1)
sid: resolved (fixed in 1.3.3.12-1)
trixie: resolved (fixed in 1.3.3.12-1)
GHSA
GHSA-2q4h-358c-9wqx: 389 Directory Server (formerly Fedora Directory Server) before 1
ghsa_unreviewed·2022-05-17
CVE-2015-3230 [HIGH] GHSA-2q4h-358c-9wqx: 389 Directory Server (formerly Fedora Directory Server) before 1
389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.
OSV
CVE-2015-3230: 389 Directory Server (formerly Fedora Directory Server) before 1
osv·2015-10-29·CVSS 7.5
CVE-2015-3230 [HIGH] CVE-2015-3230: 389 Directory Server (formerly Fedora Directory Server) before 1
389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression) [fedora-all]
bugzilla·2015-06-17·CVSS 7.5
CVE-2015-3230 [HIGH] CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression) [fedora-all]
CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)
bugzilla·2015-06-16·CVSS 7.5
CVE-2015-3230 [HIGH] CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)
CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression)
It was reported that nsSSL3Ciphers preference is not enforced server side, this
allows for a potential downgrade attack to take place.
Upstream bug report:
https://fedorahosted.org/389/ticket/48194
Discussion:
This flaw was caused by the following fix applied to 389-ds-base:
https://fedorahosted.org/389/ticket/47838
---
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1232896]
---
As noted in comment 2, this flaw was introduced as part of the fixes for issues tracked via upstream bug noted in comment 2, applied upstream via the following commits (plus few related commits updating test suite and correcting mistakes):
https://fedorahosted.org/389/changeset/13c0d2f7b
http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1230996https://fedorahosted.org/389/ticket/48194http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1230996https://fedorahosted.org/389/ticket/48194
2015-10-29
Published