|
|
Log in / Subscribe / Register

openldap: multiple vulnerabilities

Package(s):openldap CVE #(s):CVE-2011-1024 CVE-2011-1025 CVE-2011-1081
Created:March 11, 2011 Updated:September 26, 2011
Description: From the Red Hat advisory:

A flaw was found in the way OpenLDAP handled authentication failures being passed from an OpenLDAP slave to the master. If OpenLDAP was configured with a chain overlay and it forwarded authentication failures, OpenLDAP would bind to the directory as an anonymous user and return success, rather than return failure on the authenticated bind. This could allow a user on a system that uses LDAP for authentication to log into a directory-based account without knowing the password. (CVE-2011-1024)

It was found that the OpenLDAP back-ndb back end allowed successful authentication to the root distinguished name (DN) when any string was provided as a password. A remote user could use this flaw to access an OpenLDAP directory if they knew the value of the root DN. Note: This issue only affected OpenLDAP installations using the NDB back-end, which is only available for Red Hat Enterprise Linux 6 via third-party software. (CVE-2011-1025)

A flaw was found in the way OpenLDAP handled modify relative distinguished name (modrdn) requests. A remote, unauthenticated user could use this flaw to crash an OpenLDAP server via a modrdn request containing an empty old RDN value. (CVE-2011-1081)

Alerts:
Gentoo 201406-36 openldap 2014-06-30
Fedora FEDORA-2011-3627 openldap 2011-03-19
Pardus 2011-76 openldap-server 2011-05-26
SUSE SUSE-SR:2011:007 NetworkManager, OpenOffice_org, apache2-slms, dbus-1-glib, dhcp/dhcpcd/dhcp6, freetype2, kbd, krb5, libcgroup, libmodplug, libvirt, mailman, moonlight-plugin, nbd, openldap2, pure-ftpd, python-feedparser, rsyslog, telepathy-gabble, wireshark 2011-04-19
openSUSE openSUSE-SU-2011:0363-1 openldap2 2011-04-18
openSUSE openSUSE-SU-2011:0359-1 openldap2 2011-04-18
openSUSE openSUSE-SU-2011:0356-1 openldap2 2011-04-18
CentOS CESA-2011:0346 openldap 2011-04-14
Ubuntu USN-1100-1 openldap, openldap2.3 2011-03-31
Mandriva MDVSA-2011:055 openldap 2011-03-30
Mandriva MDVSA-2011:056 openldap 2011-03-30
Red Hat RHSA-2011:0346-01 openldap 2011-03-10
Red Hat RHSA-2011:0347-01 openldap 2011-03-10

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds