Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1024

Опубликовано: 28 июл. 2010
Источник: redhat
CVSS2: 5.1

Описание

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4openldapNot affected
Red Hat Enterprise Linux 5openldapFixedRHSA-2011:034610.03.2011
Red Hat Enterprise Linux 6openldapFixedRHSA-2011:034710.03.2011

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=680466openldap: forwarded bind failure messages cause success

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

nvd
больше 14 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

debian
больше 14 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-sl ...

github
около 3 лет назад

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

oracle-oval
больше 14 лет назад

ELSA-2011-0346: openldap security and bug fix update (MODERATE)

5.1 Medium

CVSS2