CVE-2012-2668

Scores

EPSS

0.006very_low0.6%
0%20%40%60%80%100%

Percentile: 0.6%

CVSS

5.0medium2.0
0246810

CVSS Score: 5.0/10

All CVSS Scores

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Description

libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhat

CWEs

CWE-200

Related Vulnerabilities

Exploits

Exploit ID: 34348

Source: exploitdb

URL: https://www.exploit-db.com/exploits/34348

Exploit ID: 35445

Source: exploitdb

URL: https://www.exploit-db.com/exploits/35445

Vulnerable Software (3)

Type: Configuration

Product: openldap

Operating System: rhel 6

Trait:
{  "fixed": "2.4.23-26.el6_3.2"}

Source: redhat

Type: Configuration

Product: openldap

Operating System: debian

Trait:
{  "unaffected": true}

Source: debian

Type: Configuration

Vendor: *

Product: openldap

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*",      "versionEndIncluding": "2.4.31",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:open...

Source: nvd

End of list