Bug ID 934934
Summary VUL-0: CVE-2015-3230: 389-ds: nsSSL3Ciphers preference not enforced server side (regression)
Classification openSUSE
Product openSUSE Factory
Version 201505*
Hardware Other
URL https://smash.suse.de/issue/117744/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee jengelh@inai.de
Reporter astieger@suse.com
QA Contact qa-bugs@suse.de
CC security-team@suse.de
Found By Security Response Team
Blocker ---

Via RH..

nsSSL3Ciphers preference not enforced server side

https://fedorahosted.org/389/changeset/53c9c4e84e3bcbc40de87b1e7cf7634d14599e1c/

> Description: The fix for ticket 47838 accidentally changed the timing
> of setting default cipher preferences and creating a sslSocket which
> broke setting the default preferences to each sslSocket.

References:
https://fedorahosted.org/389/ticket/48194
https://fedorahosted.org/389/ticket/47838
https://bugzilla.redhat.com/show_bug.cgi?id=1232096
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3230
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3230


You are receiving this mail because: