CVE Vulnerabilities

CVE-2011-1024

Published: Mar 20, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Affected Software

NameVendorStart VersionEnd Version
OpenldapOpenldap2.4.6 (including)2.4.6 (including)
OpenldapOpenldap2.4.7 (including)2.4.7 (including)
OpenldapOpenldap2.4.8 (including)2.4.8 (including)
OpenldapOpenldap2.4.9 (including)2.4.9 (including)
OpenldapOpenldap2.4.10 (including)2.4.10 (including)
OpenldapOpenldap2.4.11 (including)2.4.11 (including)
OpenldapOpenldap2.4.12 (including)2.4.12 (including)
OpenldapOpenldap2.4.13 (including)2.4.13 (including)
OpenldapOpenldap2.4.14 (including)2.4.14 (including)
OpenldapOpenldap2.4.15 (including)2.4.15 (including)
OpenldapOpenldap2.4.16 (including)2.4.16 (including)
OpenldapOpenldap2.4.17 (including)2.4.17 (including)
OpenldapOpenldap2.4.18 (including)2.4.18 (including)
OpenldapOpenldap2.4.19 (including)2.4.19 (including)
OpenldapOpenldap2.4.20 (including)2.4.20 (including)
OpenldapOpenldap2.4.21 (including)2.4.21 (including)
OpenldapOpenldap2.4.22 (including)2.4.22 (including)
OpenldapOpenldap2.4.23 (including)2.4.23 (including)
Red Hat Enterprise Linux 5RedHatopenldap-0:2.3.43-12.el5_6.7*
Red Hat Enterprise Linux 6RedHatopenldap-0:2.4.19-15.el6_0.2*
OpenldapUbuntudevel*
OpenldapUbuntukarmic*
OpenldapUbuntulucid*
OpenldapUbuntumaverick*
Openldap2.3Ubuntuhardy*

References