Cipher Preference Vulnerability in 389 Directory Server by Fedora
CVE-2015-3230

Currently unrated

Key Information:

Vendor
CVE Published:
29 October 2015

Summary

The 389 Directory Server prior to version 1.3.3.12 contains a vulnerability that fails to enforce the nsSSL3Ciphers preference when establishing SSL connections. This flaw permits attackers to request the use of ciphers that have been intentionally disabled, potentially undermining the security of encrypted communications. It significantly increases the risk of exposure to unauthorized access through weakened encryption, creating a critical need for timely updates and configurations to ensure secure setups.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.