Input validation error in OpenLDAP - CVE-2015-3276
Published: October 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input within the nss_parse_ciphers() function in libraries/libldap/tls_m.c when parsing OpenSSL-style multi-keyword mode cipher strings. A remote attacker can pass force the application to use a weaker than intended cipher.
Affected software
Splunk Enterprise
Fedora
openldap
How to mitigate CVE-2015-3276
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
openldap - update to 2.4.44-7.fc25