Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1025

Опубликовано: 29 сент. 2010
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4openldapNot affected
Red Hat Enterprise Linux 5openldapNot affected
Red Hat Enterprise Linux 6openldapFixedRHSA-2011:034710.03.2011

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=680472openldap: rootpw not verified via slapd.conf when using the NDB backend

EPSS

Процентиль: 91%
0.0728
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

nvd
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

debian
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require ...

github
около 3 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

oracle-oval
больше 14 лет назад

ELSA-2011-0347: openldap security update (MODERATE)

EPSS

Процентиль: 91%
0.0728
Низкий

6.8 Medium

CVSS2