#VU98559 Input validation error in OpenLDAP - CVE-2015-3276
Published: October 15, 2024
OpenLDAP
OpenLDAP.org
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input within the nss_parse_ciphers() function in libraries/libldap/tls_m.c when parsing OpenSSL-style multi-keyword mode cipher strings. A remote attacker can pass force the application to use a weaker than intended cipher.