CVE Vulnerabilities

CVE-2013-5185

Published: Oct 24, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple*10.8.5 (including)
Mac_os_xApple10.8.0 (including)10.8.0 (including)
Mac_os_xApple10.8.1 (including)10.8.1 (including)
Mac_os_xApple10.8.2 (including)10.8.2 (including)
Mac_os_xApple10.8.3 (including)10.8.3 (including)
Mac_os_xApple10.8.4 (including)10.8.4 (including)
Mac_os_xApple10.8.5 (including)10.8.5 (including)

References