Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2012-2668 |
CWE-ID | CWE-200 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
OpenLDAP Server applications / Directory software, identity management |
Vendor | OpenLDAP.org |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU43976
Risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2012-2668
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.
MitigationInstall update from vendor's website.
Vulnerable software versionsOpenLDAP: 2.4.6 - 2.4.30
CPE2.3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309
https://rhn.redhat.com/errata/RHSA-2012-1151.html
https://seclists.org/fulldisclosure/2019/Dec/26
https://security.gentoo.org/glsa/glsa-201406-36.xml
https://www.openldap.org/devel/gitweb.cgi?p=openldap.git;a=commitdiff;h=2c2bb2e
https://www.openldap.org/its/index.cgi?findid=7285
https://www.openwall.com/lists/oss-security/2012/06/05/4
https://www.openwall.com/lists/oss-security/2012/06/06/1
https://www.openwall.com/lists/oss-security/2012/06/06/2
https://www.securityfocus.com/bid/53823
https://www.securitytracker.com/id?1027127
https://bugzilla.redhat.com/show_bug.cgi?id=825875
https://exchange.xforce.ibmcloud.com/vulnerabilities/76099
https://seclists.org/bugtraq/2019/Dec/23
https://support.apple.com/kb/HT210788
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.