CVE-2015-3276

Impact:
Moderate
Public Date:
2015-07-15
CWE:
CWE-682
Bugzilla:
1238322: CVE-2015-3276 openldap: incorrect multi-keyword mode cipherstring parsing
A flaw was found in the way OpenLDAP parsed OpenSSL-style cipher strings. As a result, OpenLDAP could potentially use ciphers that were not intended to be enabled.

Find out more about CVE-2015-3276 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue does not affect the version of openldap package as shipped with Red Hat Enterprise Linux 5.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 7 (openldap) RHSA-2015:2131 2015-11-19

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 openldap Will not fix
Red Hat Enterprise Linux 5 openldap Not affected

Acknowledgements

This issue was discovered by Martin Poole of the Red Hat Software Maintenance Engineering group.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.