PT-2011-1103 · Openldap+1 · Openldap+1

Vincent Danen

·

Published

2011-03-10

·

Updated

2017-01-07

·

CVE-2011-1025

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenLDAP versions prior to 2.4.24 OpenLDAP versions 2.4.19 OpenLDAP version 2.4.35 and earlier
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. In OpenLDAP 2.4.x before 2.4.24, the bind.cpp in back-ndb does not require authentication for the root Distinguished Name (DN), allowing remote attackers to bypass intended access restrictions via an arbitrary password.
Recommendations For OpenLDAP versions prior to 2.4.24, update to version 2.4.24 or later. For OpenLDAP versions 2.4.19, update to a version later than 2.4.19. For OpenLDAP version 2.4.35 and earlier, update to a version later than 2.4.35. As a temporary workaround, consider restricting access to the back-ndb module until a patch is available.

Fix

Improper Certificate Validation

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06163
BDU:2015-06459
BDU:2015-06460
BDU:2015-06461
BDU:2015-06462
BDU:2015-06463
BDU:2015-06464
BDU:2015-09683
CVE-2011-1025
RHSA-2011:0347
RHSA-2011_0347

Affected Products

Openldap
Red Hat