Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-1024

Опубликовано: 20 мар. 2011
Источник: debian
EPSS Низкий

Описание

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openldapfixed2.4.25-1package
openldapfixed2.4.11-1+lenny2.1lennypackage
openldapfixed2.4.23-7.1squeezepackage

EPSS

Процентиль: 48%
0.00247
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

redhat
почти 15 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

nvd
больше 14 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

github
около 3 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

oracle-oval
больше 14 лет назад

ELSA-2011-0346: openldap security and bug fix update (MODERATE)

EPSS

Процентиль: 48%
0.00247
Низкий
Уязвимость CVE-2011-1024