CVE-2011-1025

NameCVE-2011-1025
Descriptionbind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs617606

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openldap (PTS)jessie, jessie (lts)2.4.40+dfsg-1+deb8u11fixed
stretch (security), stretch (lts), stretch2.4.44+dfsg-5+deb9u9fixed
buster (security), buster, buster (lts)2.4.47+dfsg-3+deb10u7fixed
bullseye (security), bullseye2.4.57+dfsg-3+deb11u1fixed
bookworm2.5.13+dfsg-5fixed
sid, trixie2.5.18+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openldapsourcesqueeze2.4.23-7.1
openldapsource(unstable)2.4.25-1unimportant617606

Notes

NBD backend disabled in Debian builds

Search for package or bug name: Reporting problems