CVE-2015-3230
Summary
| CVE | CVE-2015-3230 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-29 20:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | 389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12 does not enforce the nsSSL3Ciphers preference when creating an sslSocket, which allows remote attackers to have unspecified impact by requesting to use a disabled cipher. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fedoraproject | 389 Directory Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 1230996 – nsSSL3Ciphers preference not enforced server side (regression) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| #48194 (nsSSL3Ciphers preference not enforced server side (regression)) – 389 Project | af854a3a-2127-422b-91ae-364da2661108 | fedorahosted.org | |
| [SECURITY] Fedora 21 Update: 389-ds-base-1.3.3.13-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| 389 Directory Server - Releases/1.3.3.12 | af854a3a-2127-422b-91ae-364da2661108 | directory.fedoraproject.org | Patch, Vendor Advisory |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2015-3230 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 1232096 – (CVE-2015-3230) CVE-2015-3230 389-ds-base: nsSSL3Ciphers preference not enforced server side (regression) | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.