CVE-2015-3250: Infoleak
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
Other sources
Apache Directory LDAP API version 1.0.0-M31 fixes an unspecified timing attack vulnerability.
External References:
http://directory.apache.org/api/#news
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3250?
CVE-2015-3250 has a moderate severity level due to the potential for timing attacks.
How do I fix CVE-2015-3250?
To fix CVE-2015-3250, upgrade to Apache Directory LDAP API version 1.0.0-M31 or later.
What is a timing attack in the context of CVE-2015-3250?
A timing attack related to CVE-2015-3250 allows attackers to gain information based on the time taken to process their requests.
What versions are affected by CVE-2015-3250?
CVE-2015-3250 affects Apache Directory LDAP API versions prior to 1.0.0-M31.
Is CVE-2015-3250 an exploit in the Apache Directory LDAP API?
Yes, CVE-2015-3250 is a vulnerability in the Apache Directory LDAP API that can be exploited through timing attacks.