CVE Vulnerabilities

CVE-2011-1024

Published: Mar 20, 2011 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Affected Software

Name Vendor Start Version End Version
Openldap Openldap 2.4.6 (including) 2.4.6 (including)
Openldap Openldap 2.4.7 (including) 2.4.7 (including)
Openldap Openldap 2.4.8 (including) 2.4.8 (including)
Openldap Openldap 2.4.9 (including) 2.4.9 (including)
Openldap Openldap 2.4.10 (including) 2.4.10 (including)
Openldap Openldap 2.4.11 (including) 2.4.11 (including)
Openldap Openldap 2.4.12 (including) 2.4.12 (including)
Openldap Openldap 2.4.13 (including) 2.4.13 (including)
Openldap Openldap 2.4.14 (including) 2.4.14 (including)
Openldap Openldap 2.4.15 (including) 2.4.15 (including)
Openldap Openldap 2.4.16 (including) 2.4.16 (including)
Openldap Openldap 2.4.17 (including) 2.4.17 (including)
Openldap Openldap 2.4.18 (including) 2.4.18 (including)
Openldap Openldap 2.4.19 (including) 2.4.19 (including)
Openldap Openldap 2.4.20 (including) 2.4.20 (including)
Openldap Openldap 2.4.21 (including) 2.4.21 (including)
Openldap Openldap 2.4.22 (including) 2.4.22 (including)
Openldap Openldap 2.4.23 (including) 2.4.23 (including)

References