CVE-2012-2668
openldap: does not honor TLSCipherSuite settings
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.
libraries/libldap/tls_m.c en OpenLDAP, posiblemente v2.4.31 y anteriores, cuando se utiliza el "backend" de Mozilla NSS, siempre utiliza la suite de cifrado por defecto incluso cuando TLSCipherSuite está establecido, lo que podría provocar que OpenLDAP use algoritmos de cifrado más débiles que los esperados y que sea más fácil para que los atacantes remotos obtener información sensible.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-05-14 CVE Reserved
- 2012-06-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309 | X_refsource_misc | |
http://seclists.org/fulldisclosure/2019/Dec/26 | Mailing List | |
http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commitdiff%3Bh=2c2bb2e | X_refsource_confirm | |
http://www.openldap.org/its/index.cgi?findid=7285 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2012/06/05/4 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/06/06/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/06/06/2 | Mailing List | |
http://www.securityfocus.com/bid/53823 | Vdb Entry | |
http://www.securitytracker.com/id?1027127 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76099 | Vdb Entry | |
https://seclists.org/bugtraq/2019/Dec/23 | Mailing List | |
https://support.apple.com/kb/HT210788 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2012-1151.html | 2023-02-13 | |
http://security.gentoo.org/glsa/glsa-201406-36.xml | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=825875 | 2012-08-08 | |
https://access.redhat.com/security/cve/CVE-2012-2668 | 2012-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | <= 2.4.31 Search vendor "Openldap" for product "Openldap" and version " <= 2.4.31" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.6 Search vendor "Openldap" for product "Openldap" and version "2.4.6" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.7 Search vendor "Openldap" for product "Openldap" and version "2.4.7" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.8 Search vendor "Openldap" for product "Openldap" and version "2.4.8" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.9 Search vendor "Openldap" for product "Openldap" and version "2.4.9" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.10 Search vendor "Openldap" for product "Openldap" and version "2.4.10" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.11 Search vendor "Openldap" for product "Openldap" and version "2.4.11" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.12 Search vendor "Openldap" for product "Openldap" and version "2.4.12" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.13 Search vendor "Openldap" for product "Openldap" and version "2.4.13" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.14 Search vendor "Openldap" for product "Openldap" and version "2.4.14" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.15 Search vendor "Openldap" for product "Openldap" and version "2.4.15" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.16 Search vendor "Openldap" for product "Openldap" and version "2.4.16" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.17 Search vendor "Openldap" for product "Openldap" and version "2.4.17" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.18 Search vendor "Openldap" for product "Openldap" and version "2.4.18" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.19 Search vendor "Openldap" for product "Openldap" and version "2.4.19" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.20 Search vendor "Openldap" for product "Openldap" and version "2.4.20" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.21 Search vendor "Openldap" for product "Openldap" and version "2.4.21" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.22 Search vendor "Openldap" for product "Openldap" and version "2.4.22" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.23 Search vendor "Openldap" for product "Openldap" and version "2.4.23" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.24 Search vendor "Openldap" for product "Openldap" and version "2.4.24" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.25 Search vendor "Openldap" for product "Openldap" and version "2.4.25" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.26 Search vendor "Openldap" for product "Openldap" and version "2.4.26" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.27 Search vendor "Openldap" for product "Openldap" and version "2.4.27" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.28 Search vendor "Openldap" for product "Openldap" and version "2.4.28" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.29 Search vendor "Openldap" for product "Openldap" and version "2.4.29" | - |
Affected
| ||||||
Openldap Search vendor "Openldap" | Openldap Search vendor "Openldap" for product "Openldap" | 2.4.30 Search vendor "Openldap" for product "Openldap" and version "2.4.30" | - |
Affected
|