CVE-2011-1025
Publication date 19 March 2011
Last updated 24 July 2024
Ubuntu priority
Description
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openldap | ||
| openldap2.2 | ||
| openldap2.3 | ||
Notes
Patch details
| Package | Patch details |
|---|---|
| openldap |
References
Related Ubuntu Security Notices (USN)
- USN-1100-1
- OpenLDAP vulnerabilities
- 31 March 2011