ubuntu · CVE-2015-3276

Quick triage

Priority: negligible Published: 2015-12-07 20:59:00 UTC Updated: 2025-08-25 21:38:13 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-3276 negligible priority: Ubuntu including 1 source packages (openldap), 5 status rows across 5 suites (precise, trusty, upstream, utopic, vivid): not-affected 3, ignored 1, needs-triage 1.

Description:

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

cvelogic Threat Intelligence