PT-2011-1102 · Openldap+1 · Openldap-Clients+8

Published

2011-03-10

·

Updated

2017-01-07

·

CVE-2011-1024

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.4.24 OpenLDAP versions 2.3.43 OpenLDAP versions 2.4.19 OpenLDAP-servers versions 2.3.43 OpenLDAP-servers versions 2.4.19 OpenLDAP-clients versions 2.3.43 OpenLDAP-clients versions 2.4.19 OpenLDAP-devel versions 2.3.43 OpenLDAP-devel versions 2.4.19 OpenLDAP-debuginfo versions 2.4.19 OpenLDAP-servers-sql versions 2.3.43 OpenLDAP-servers-sql versions 2.4.19 OpenLDAP-servers-overlays versions 2.3.43 compat-openldap versions 2.3.43 2.2.29 compat-openldap versions 2.3.43 2.3.43
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely by an attacker who has passed the authentication procedure. The vulnerability is related to the chain overlay and ppolicy forward updates in master-slave configurations, allowing remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.
Recommendations For OpenLDAP versions prior to 2.4.24, update to version 2.4.24 or later. For OpenLDAP versions 2.3.43, update to a newer version. For OpenLDAP versions 2.4.19, update to version 2.4.24 or later. For OpenLDAP-servers versions 2.3.43, update to a newer version. For OpenLDAP-servers versions 2.4.19, update to version 2.4.24 or later. For OpenLDAP-clients versions 2.3.43, update to a newer version. For OpenLDAP-clients versions 2.4.19, update to version 2.4.24 or later. For OpenLDAP-devel versions 2.3.43, update to a newer version. For OpenLDAP-devel versions 2.4.19, update to version 2.4.24 or later. For OpenLDAP-debuginfo versions 2.4.19, update to version 2.4.24 or later. For OpenLDAP-servers-sql versions 2.3.43, update to a newer version. For OpenLDAP-servers-sql versions 2.4.19, update to version 2.4.24 or later. For OpenLDAP-servers-overlays versions 2.3.43, update to a newer version. For compat-openldap versions 2.3.43 2.2.29, update to a newer version. For compat-openldap versions 2.3.43 2.3.43, update to a newer version. As a temporary workaround, consider disabling the chain overlay and ppolicy forward updates until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the password variable in the affected API endpoints until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06163
BDU:2015-06459
BDU:2015-06460
BDU:2015-06461
BDU:2015-06462
BDU:2015-06463
BDU:2015-06464
BDU:2015-07177
BDU:2015-07453
BDU:2015-07455
BDU:2015-07457
BDU:2015-07459
BDU:2015-07460
BDU:2015-07461
BDU:2015-08718
BDU:2015-08719
BDU:2015-08720
BDU:2015-08721
BDU:2015-08722
BDU:2015-08723
BDU:2015-08724
BDU:2015-09683
CVE-2011-1024
RHSA-2011:0346
RHSA-2011:0347
RHSA-2011_0346
RHSA-2011_0347

Affected Products

Openldap
Openldap-Clients
Openldap-Debuginfo
Openldap-Devel
Openldap-Servers
Openldap-Servers-Overlays
Openldap-Servers-Sql
Red Hat
Compat-Openldap