CVE Vulnerabilities

CVE-2015-3230

Published: Oct 29, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.

Affected Software

Name Vendor Start Version End Version
389_directory_server Fedoraproject * 1.3.3.10 (including)
Red Hat Enterprise Linux 7 RedHat 389-ds-base-0:1.3.3.1-20.ael7b_1 *
389-ds-base Ubuntu precise *
389-ds-base Ubuntu trusty *
389-ds-base Ubuntu utopic *
389-ds-base Ubuntu vivid *
389-ds-base Ubuntu wily *
389-ds-base Ubuntu xenial *

References