Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-1025

Опубликовано: 20 мар. 2011
Источник: debian

Описание

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openldapfixed2.4.25-1package
openldapfixed2.4.23-7.1squeezepackage

Примечания

  • NBD backend disabled in Debian builds

Связанные уязвимости

ubuntu
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

redhat
около 15 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

nvd
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

github
больше 3 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

oracle-oval
больше 14 лет назад

ELSA-2011-0347: openldap security update (MODERATE)