Description
389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
https://fedorahosted.org/389/ticket/48194
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1230996
Patch, Vendor Advisory x_refsource_confirm
http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-12.html
Scores
EPSS
0.0257
EPSS Percentile
83.5%
Details
CWE
CWE-254
Status
published
Products (1)
fedoraproject/389_directory_server
< 1.3.3.10
Published
Oct 29, 2015
Tracked Since
Feb 18, 2026