The nss_parse_ciphers function in libraries/libldap/tls_m...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 28, 2023
Description
Published by the National Vulnerability Database
Dec 7, 2015
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 28, 2023
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
References