Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-1025
Description:bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
Test IDs: 1.3.6.1.4.1.25623.1.0.69514   1.3.6.1.4.1.25623.1.0.70338   1.3.6.1.4.1.25623.1.0.122219  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-1025
1025190
http://securitytracker.com/id?1025190
43331
http://secunia.com/advisories/43331
43718
http://secunia.com/advisories/43718
ADV-2011-0665
http://www.vupen.com/english/advisories/2011/0665
GLSA-201406-36
http://security.gentoo.org/glsa/glsa-201406-36.xml
MDVSA-2011:056
http://www.mandriva.com/security/advisories?name=MDVSA-2011:056
RHSA-2011:0347
http://www.redhat.com/support/errata/RHSA-2011-0347.html
USN-1100-1
http://www.ubuntu.com/usn/USN-1100-1
[openldap-announce] 20110212 OpenLDAP 2.4.24 available
http://www.openldap.org/lists/openldap-announce/201102/msg00000.html
[oss-security] 20110224 CVE Request -- OpenLDAP -- two issues
http://openwall.com/lists/oss-security/2011/02/24/12
[oss-security] 20110225 Re: CVE Request -- OpenLDAP -- two issue
http://openwall.com/lists/oss-security/2011/02/25/13
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ndb/bind.cpp.diff?r1=1.5&r2=1.8
http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ndb/bind.cpp.diff?r1=1.5&r2=1.8
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6661
http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6661
https://bugzilla.redhat.com/show_bug.cgi?id=680472
https://bugzilla.redhat.com/show_bug.cgi?id=680472




© 1998-2025 E-Soft Inc. All rights reserved.