The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
Incorrect Calculation
-
Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
debian/openldap | deb | debian | 12 | >=2.5.13+dfsg-5 | Not yet available |
debian/openldap | deb | debian | 11 | >=2.4.57+dfsg-3+deb11u1 | Not yet available |
debian/openldap | deb | debian | 13 | >=2.5.17+dfsg-1 | Not yet available |
debian/openldap | deb | debian | unstable | >=2.5.17+dfsg-1 | Not yet available |
debian/openldap | deb | debian | 10 | >=2.4.47+dfsg-3+deb10u7 | Not yet available |
Severity and metrics
No CVSS data available from this source.
3.9
3.9
-
8.6
-