Описание
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | released | 2.4.23-6ubuntu6 |
hardy | DNE | |
karmic | released | 2.4.18-0ubuntu1.2 |
lucid | released | 2.4.21-0ubuntu5.4 |
maverick | released | 2.4.23-0ubuntu3.5 |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | not-affected | code not present |
devel | DNE | |
hardy | DNE | |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | not-affected | code not present |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
upstream | needs-triage |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require ...
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
EPSS
6.8 Medium
CVSS2