The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openldap | Openldap | * | 2.5 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | openldap-0:2.4.40-8.el7 | * |
Openldap | Ubuntu | utopic | * |