CVE-2011-1025
Publication date 19 March 2011
Last updated 24 July 2024
Ubuntu priority
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
Status
Package | Ubuntu Release | Status |
---|---|---|
openldap | 10.10 maverick |
Fixed 2.4.23-0ubuntu3.5
|
10.04 LTS lucid |
Fixed 2.4.21-0ubuntu5.4
|
|
9.10 karmic |
Fixed 2.4.18-0ubuntu1.2
|
|
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
openldap2.2 | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper |
Not affected
|
|
openldap2.3 | 10.10 maverick | Not in release |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
8.04 LTS hardy |
Not affected
|
|
6.06 LTS dapper | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
openldap |
References
Related Ubuntu Security Notices (USN)
- USN-1100-1
- OpenLDAP vulnerabilities
- 31 March 2011