Vulnonym.com

CVE-2012-2668 - Accurate Monoliths

Description

libraries/libldap/tls_m.c in OpenLDAP possibly 2.4.31 and earlier when using the Mozilla NSS backend always uses the default cipher suite even when TLSCipherSuite is set which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

Reference

http://www.openwall.com/lists/oss-security/2012/06/06/1 http://www.securitytracker.com/id?1027127 http://www.securityfocus.com/bid/53823 http://www.openwall.com/lists/oss-security/2012/06/06/2 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309 https://bugzilla.redhat.com/show_bug.cgi?id=825875 http://www.openwall.com/lists/oss-security/2012/06/05/4 http://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commitdiff;h=2c2bb2e http://www.openldap.org/its/index.cgi?findid=7285 http://rhn.redhat.com/errata/RHSA-2012-1151.html http://security.gentoo.org/glsa/glsa-201406-36.xml https://exchange.xforce.ibmcloud.com/vulnerabilities/76099 https://support.apple.com/kb/HT210788 https://seclists.org/bugtraq/2019/Dec/23 http://seclists.org/fulldisclosure/2019/Dec/26