Bug#676309: openldap: CVE-2012-2668

2012-06-05 Thread Henri Salo
Then it does not affect Debian. I did not know this detail as I am not the user of this package. I thought it is better to report this issue to get information public. I can add this detail to Debian security tracker and close this bug. - Henri Salo -- To UNSUBSCRIBE, email to debian-bugs-di

Bug#676309: [Pkg-openldap-devel] Bug#676309: openldap: CVE-2012-2668 does not honor TLSCipherSuite settings

2012-06-05 Thread Steve Langasek
On Wed, Jun 06, 2012 at 08:01:38AM +0300, Henri Salo wrote: > Package: openldap > Version: 2.4.23-7.2 > Severity: important > Tags: security > https://bugzilla.redhat.com/show_bug.cgi?id=825875 > """ > It was reported that OpenLDAP, when using the Mozilla NSS backend, would > ignore any TLSCipherS

Bug#676309: openldap: CVE-2012-2668 does not honor TLSCipherSuite settings

2012-06-05 Thread Henri Salo
Package: openldap Version: 2.4.23-7.2 Severity: important Tags: security https://bugzilla.redhat.com/show_bug.cgi?id=825875 """ It was reported that OpenLDAP, when using the Mozilla NSS backend, would ignore any TLSCipherSuite configuration settings. When the TLSCipherSuite setting is configure