The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openldap | Openldap | * | 2.5 (excluding) |
| Red Hat Enterprise Linux 7 | RedHat | openldap-0:2.4.40-8.el7 | * |
| Openldap | Ubuntu | utopic | * |