Advisory Published
Updated

REDHAT-BUG-825875

First published: Mon May 28 2012(Updated: )

It was reported that OpenLDAP, when using the Mozilla NSS backend, would ignore any TLSCipherSuite configuration settings. When the TLSCipherSuite setting is configured, OpenLDAP would use the default cipher suite, ignoring the setting. While the default cipher suite contains some weak ciphers (e.g. MD5-based), it is still not easy to break the encryption to obtain sensitive information. However, if an administrator wishes to enforce the use of stronger ciphers by overriding the defaults using TLSCipherSuite, they should be able to trust that, when the configuration items is in place, the stronger ciphers are used. Due to this flaw, that is not the case.

Affected SoftwareAffected VersionHow to fix
OpenLDAP

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-825875?

    The severity of REDHAT-BUG-825875 is considered high due to the use of weak default ciphers.

  • How do I fix REDHAT-BUG-825875?

    To fix REDHAT-BUG-825875, update your OpenLDAP configuration to explicitly set the TLSCipherSuite parameter using a secure cipher.

  • Which versions of OpenLDAP are affected by REDHAT-BUG-825875?

    REDHAT-BUG-825875 affects OpenLDAP installations that utilize the Mozilla NSS backend.

  • What are the potential risks associated with REDHAT-BUG-825875?

    The risks associated with REDHAT-BUG-825875 include potential exposure to cryptographic vulnerabilities due to weak ciphers.

  • Is there a workaround for REDHAT-BUG-825875?

    A temporary workaround for REDHAT-BUG-825875 is to manually override the default cipher suite settings until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203