CVE-2011-1025
CVE-2011-1025
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://openwall.com/lists/oss-security/2011/02/24/12http://openwall.com/lists/oss-security/2011/02/25/13https://bugzilla.redhat.com/show_bug.cgi?id=680472http://secunia.com/advisories/43331http://secunia.com/advisories/43718http://security.gentoo.org/glsa/glsa-201406-36.xmlhttp://securitytracker.com/id?1025190http://www.mandriva.com/security/advisories?name=MDVSA-2011:056http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ndb/bind.cpp.diff?r1=1.5&r2=1.8http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6661http://www.openldap.org/lists/openldap-announce/201102/msg00000.html