LWN.net Logo

openldap: weaker than expected encryption

Package(s):openldap CVE #(s):CVE-2012-2668
Created:July 17, 2012 Updated:August 9, 2012
Description: From the CVE entry:

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

Alerts:
Fedora FEDORA-2012-10000 2012-07-17
Fedora FEDORA-2012-10023 2012-07-17
Red Hat RHSA-2012:1151-01 2012-08-08
CentOS CESA-2012:1151 2012-08-08
Oracle ELSA-2012-1151 2012-08-08
Scientific Linux SL-open-20120808 2012-08-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds