CVE-2015-3230

389 Directory Server <1.3.3.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher.

References (4)

Core 4
Core References
Various Sources x_refsource_confirm
https://fedorahosted.org/389/ticket/48194
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/168985.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1230996

Scores

EPSS 0.0257
EPSS Percentile 83.5%

Details

CWE
CWE-254
Status published
Products (1)
fedoraproject/389_directory_server < 1.3.3.10
Published Oct 29, 2015
Tracked Since Feb 18, 2026