The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade openldap | Feb 15, 2017 | Dec 7, 2015 |
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Oracle_linux | — | Upgrade openldap-servers-sqlUpgrade openldap-clientsUpgrade openldap-develUpgrade openldap-serversUpgrade openldap | Oct 16, 2024 | Dec 7, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 15, 2015 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.2.3Upgrade Splunk Enterprise to version 9.3.1Upgrade Splunk Enterprise to version 9.1.6 | Sep 30, 2025 | Dec 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub