389 Directory Server nsSSL3Ciphers preference Vulnerability (CVE-2015-3230)
389 Directory Server nsSSL3Ciphers preference Vulnerability (CVE-2015-3230)
Release date:
Updated on:
Affected Systems:
389 Directory Server 389 Directory Server <1.3.3.12
Description:
CVE (CAN) ID: CVE-2015-3230
389 Directory Server is an LDAP Server developed by Red Hat.
When sslSocket is created in versions earlier than 389 Directory Server 1.3.3.12, nsSSL3Ciphers preferences are not implemented. Remote attackers can exploit this vulnerability to initiate security attacks by requesting a disabled password group.
<* Source: nsSSL3Ciphers
*>
Suggestion:
Vendor patch:
389 Directory Server
--------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://fedorahosted.org/389/ticket/48194
Http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.html
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1230996
This article permanently updates the link address: