CVE Vulnerabilities

CVE-2011-1024

Published: Mar 20, 2011 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Affected Software

Name Vendor Start Version End Version
Openldap Openldap 2.4.6 (including) 2.4.6 (including)
Openldap Openldap 2.4.7 (including) 2.4.7 (including)
Openldap Openldap 2.4.8 (including) 2.4.8 (including)
Openldap Openldap 2.4.9 (including) 2.4.9 (including)
Openldap Openldap 2.4.10 (including) 2.4.10 (including)
Openldap Openldap 2.4.11 (including) 2.4.11 (including)
Openldap Openldap 2.4.12 (including) 2.4.12 (including)
Openldap Openldap 2.4.13 (including) 2.4.13 (including)
Openldap Openldap 2.4.14 (including) 2.4.14 (including)
Openldap Openldap 2.4.15 (including) 2.4.15 (including)
Openldap Openldap 2.4.16 (including) 2.4.16 (including)
Openldap Openldap 2.4.17 (including) 2.4.17 (including)
Openldap Openldap 2.4.18 (including) 2.4.18 (including)
Openldap Openldap 2.4.19 (including) 2.4.19 (including)
Openldap Openldap 2.4.20 (including) 2.4.20 (including)
Openldap Openldap 2.4.21 (including) 2.4.21 (including)
Openldap Openldap 2.4.22 (including) 2.4.22 (including)
Openldap Openldap 2.4.23 (including) 2.4.23 (including)
Red Hat Enterprise Linux 5 RedHat openldap-0:2.3.43-12.el5_6.7 *
Red Hat Enterprise Linux 6 RedHat openldap-0:2.4.19-15.el6_0.2 *
Openldap Ubuntu devel *
Openldap Ubuntu karmic *
Openldap Ubuntu lucid *
Openldap Ubuntu maverick *
Openldap2.3 Ubuntu hardy *

References