CVE-2012-2668
Estado: ModificadaMedia (4.3)—
libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.95%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309
- http://rhn.redhat.com/errata/RHSA-2012-1151.html
- http://seclists.org/fulldisclosure/2019/Dec/26
- http://security.gentoo.org/glsa/glsa-201406-36.xml
- http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commitdiff%3Bh=2c2bb2e
- http://www.openldap.org/its/index.cgi?findid=7285
- http://www.openwall.com/lists/oss-security/2012/06/05/4
- http://www.openwall.com/lists/oss-security/2012/06/06/1
- http://www.openwall.com/lists/oss-security/2012/06/06/2
- http://www.securityfocus.com/bid/53823
- http://www.securitytracker.com/id?1027127
- https://bugzilla.redhat.com/show_bug.cgi?id=825875
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76099
- https://seclists.org/bugtraq/2019/Dec/23
- https://support.apple.com/kb/HT210788
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309
- http://rhn.redhat.com/errata/RHSA-2012-1151.html
- http://seclists.org/fulldisclosure/2019/Dec/26
- http://security.gentoo.org/glsa/glsa-201406-36.xml
- http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commitdiff%3Bh=2c2bb2e
- http://www.openldap.org/its/index.cgi?findid=7285
- http://www.openwall.com/lists/oss-security/2012/06/05/4
- http://www.openwall.com/lists/oss-security/2012/06/06/1
- http://www.openwall.com/lists/oss-security/2012/06/06/2
- http://www.securityfocus.com/bid/53823
- http://www.securitytracker.com/id?1027127
- https://bugzilla.redhat.com/show_bug.cgi?id=825875
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76099
- https://seclists.org/bugtraq/2019/Dec/23
- https://support.apple.com/kb/HT210788
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-2668",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-06-17T03:41:41.030",
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-1151.html",
"source": "secalert@redhat.com"
},
{
"url": "http://seclists.org/fulldisclosure/2019/Dec/26",
"source": "secalert@redhat.com"
},
{
"url": "http://security.gentoo.org/glsa/glsa-201406-36.xml",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commitdiff%3Bh=2c2bb2e",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openldap.org/its/index.cgi?findid=7285",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/05/4",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/06/1",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/06/2",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/53823",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securitytracker.com/id?1027127",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=825875",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76099",
"source": "secalert@redhat.com"
},
{
"url": "https://seclists.org/bugtraq/2019/Dec/23",
"source": "secalert@redhat.com"
},
{
"url": "https://support.apple.com/kb/HT210788",
"source": "secalert@redhat.com"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676309",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-1151.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2019/Dec/26",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-201406-36.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openldap.org/devel/gitweb.cgi?p=openldap.git%3Ba=commitdiff%3Bh=2c2bb2e",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openldap.org/its/index.cgi?findid=7285",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/05/4",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/06/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/06/06/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/53823",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1027127",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=825875",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76099",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://seclists.org/bugtraq/2019/Dec/23",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/kb/HT210788",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information."
},
{
"lang": "es",
"value": "libraries/libldap/tls_m.c en OpenLDAP, posiblemente v2.4.31 y anteriores, cuando se utiliza el \"backend\" de Mozilla NSS, siempre utiliza la suite de cifrado por defecto incluso cuando TLSCipherSuite está establecido, lo que podría provocar que OpenLDAP use algoritmos de cifrado más débiles que los esperados y que sea más fácil para que los atacantes remotos obtener información sensible."
}
],
"lastModified": "2026-06-16T23:41:50.607",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D85D909A-036F-41CB-ADA1-A374562241F8",
"versionEndIncluding": "2.4.31"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5EC66226-A597-4A4C-932F-F4A7BAE119C8"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AEABC84-7B67-4FD4-A891-E52C80DC881E"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "340F673A-295E-4B75-A9D1-E785B0440BE6"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49203E99-71E2-49D4-91A0-65AAAA7DC18F"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "473AEC48-FBBF-4BEB-8728-1FA80DD94807"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B0415EA-5F21-44C3-93F3-DDADBAA64449"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16AFC655-E81F-4FDE-8030-9781A8B79E73"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E99FB859-D023-4B2B-A709-05E83A46E2A1"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D2EEBC7-1FAF-43E2-A124-C387C02D9E2B"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95D242E4-D5EB-4785-A6EF-60B1E8E2B0EC"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6FEDD9C-FDF7-456A-B06C-0A4A4443991D"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9245CDE2-B90A-4D47-BA20-A7869FF0A645"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB993E4D-E573-4495-97DE-465DDB2AA2DF"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0F106A3-63D5-4D07-9440-6628DBA78BE5"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36CC03BC-DF34-43CD-90B0-27D23A1DD06A"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16C90FEE-527E-47F5-8840-517A55163D8E"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0FAEA812-BB47-47A3-A975-B3B8D30DBA36"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.23:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DE5D180-3972-40A0-ADAF-A4F3364D1381"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.24:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD76F376-00D8-4917-BF68-6EECC316C331"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.25:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7063C11-3BF5-4037-ADC3-0C7E9AF830B4"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.26:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAE258EA-1B57-4189-AD5A-7E2ACF223167"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.27:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C492F5F5-A6FD-4BED-890A-79254138CC0A"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.28:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6F7FDE8-2E54-4162-AA5F-D81253AAC8FA"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "693E3145-FDDB-4780-886B-6D7FC7B2C5B3"
},
{
"criteria": "cpe:2.3:a:openldap:openldap:2.4.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1BF32056-CC6A-4B2B-8FAA-F573445B9B99"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}