{"api_version":"1","generated_at":"2026-07-22T23:41:12+00:00","cve":"CVE-2011-1024","urls":{"html":"https://cve.report/CVE-2011-1024","api":"https://cve.report/api/cve/CVE-2011-1024.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1024","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1024"},"summary":{"title":"CVE-2011-1024","description":"chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.","state":"PUBLISHED","assigner":"redhat","published_at":"2011-03-20 02:00:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:N/AC:H/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607","name":"http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenLDAP ITS - Software Bugs/6607","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-1100-1","name":"http://www.ubuntu.com/usn/USN-1100-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-1100-1: OpenLDAP vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43708","name":"http://secunia.com/advisories/43708","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA43708 - Red Hat update for openldap - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0347.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0347.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/02/24/12","name":"http://openwall.com/lists/oss-security/2011/02/24/12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE Request -- OpenLDAP -- two issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:055","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:055","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2011:055 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43331","name":"http://secunia.com/advisories/43331","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"OpenLDAP Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=680466","name":"https://bugzilla.redhat.com/show_bug.cgi?id=680466","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"680466 – (CVE-2011-1024) CVE-2011-1024 openldap: forwarded bind failure messages cause success","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/02/25/13","name":"http://openwall.com/lists/oss-security/2011/02/25/13","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE Request -- OpenLDAP -- two issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0665","name":"http://www.vupen.com/english/advisories/2011/0665","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.novell.com/show_bug.cgi?id=674985","name":"https://bugzilla.novell.com/show_bug.cgi?id=674985","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0","name":"http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0346.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0346.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1025188","name":"http://securitytracker.com/id?1025188","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenLDAP Forwarding Error May Let Remote Users Bypass Authentication for External Applications - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43718","name":"http://secunia.com/advisories/43718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for openldap - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:056","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:056","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2011:056 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openldap.org/lists/openldap-technical/201004/msg00247.html","name":"http://www.openldap.org/lists/openldap-technical/201004/msg00247.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ppolicy master/slave issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735","name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"2016-04 Security Bulletin: CTP Series: Multiple vulnerabilities in CTP Series - Juniper Networks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openldap.org/lists/openldap-announce/201102/msg00000.html","name":"http://www.openldap.org/lists/openldap-announce/201102/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"OpenLDAP 2.4.24 available","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-201406-36.xml","name":"http://security.gentoo.org/glsa/glsa-201406-36.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  OpenLDAP: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1024","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1024","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.23","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1024","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openldap","cpe5":"openldap","cpe6":"2.4.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:14:27.232Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-201406-36","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201406-36.xml"},{"name":"RHSA-2011:0346","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0346.html"},{"name":"1025188","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1025188"},{"name":"43708","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43708"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607"},{"name":"[openldap-technical] 20100429 ppolicy master/slave issue","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openldap.org/lists/openldap-technical/201004/msg00247.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0"},{"name":"[openldap-announce] 20110212 OpenLDAP 2.4.24 available","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openldap.org/lists/openldap-announce/201102/msg00000.html"},{"name":"MDVSA-2011:056","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:056"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.novell.com/show_bug.cgi?id=674985"},{"name":"[oss-security] 20110225 Re: CVE Request -- OpenLDAP -- two issues","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/02/25/13"},{"name":"RHSA-2011:0347","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0347.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"name":"MDVSA-2011:055","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:055"},{"name":"43718","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43718"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=680466"},{"name":"[oss-security] 20110224 CVE Request -- OpenLDAP -- two issues","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/02/24/12"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735"},{"name":"USN-1100-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1100-1"},{"name":"ADV-2011-0665","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0665"},{"name":"43331","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43331"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-04-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-01-04T17:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"GLSA-201406-36","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201406-36.xml"},{"name":"RHSA-2011:0346","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0346.html"},{"name":"1025188","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1025188"},{"name":"43708","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43708"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6607"},{"name":"[openldap-technical] 20100429 ppolicy master/slave issue","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openldap.org/lists/openldap-technical/201004/msg00247.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.openldap.org/devel/cvsweb.cgi/servers/slapd/back-ldap/chain.c.diff?r1=1.76&r2=1.77&hideattic=1&sortbydate=0"},{"name":"[openldap-announce] 20110212 OpenLDAP 2.4.24 available","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openldap.org/lists/openldap-announce/201102/msg00000.html"},{"name":"MDVSA-2011:056","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:056"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.novell.com/show_bug.cgi?id=674985"},{"name":"[oss-security] 20110225 Re: CVE Request -- OpenLDAP -- two issues","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/02/25/13"},{"name":"RHSA-2011:0347","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0347.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705"},{"name":"MDVSA-2011:055","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:055"},{"name":"43718","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43718"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=680466"},{"name":"[oss-security] 20110224 CVE Request -- OpenLDAP -- two issues","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/02/24/12"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735"},{"name":"USN-1100-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1100-1"},{"name":"ADV-2011-0665","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0665"},{"name":"43331","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43331"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-1024","datePublished":"2011-03-20T01:00:00.000Z","dateReserved":"2011-02-14T00:00:00.000Z","dateUpdated":"2024-08-06T22:14:27.232Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-03-20 02:00:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.6:*:*:*:*:*:*:*","matchCriteriaId":"5EC66226-A597-4A4C-932F-F4A7BAE119C8"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.7:*:*:*:*:*:*:*","matchCriteriaId":"4AEABC84-7B67-4FD4-A891-E52C80DC881E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.8:*:*:*:*:*:*:*","matchCriteriaId":"340F673A-295E-4B75-A9D1-E785B0440BE6"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.9:*:*:*:*:*:*:*","matchCriteriaId":"49203E99-71E2-49D4-91A0-65AAAA7DC18F"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.10:*:*:*:*:*:*:*","matchCriteriaId":"473AEC48-FBBF-4BEB-8728-1FA80DD94807"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.11:*:*:*:*:*:*:*","matchCriteriaId":"7B0415EA-5F21-44C3-93F3-DDADBAA64449"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.12:*:*:*:*:*:*:*","matchCriteriaId":"16AFC655-E81F-4FDE-8030-9781A8B79E73"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.13:*:*:*:*:*:*:*","matchCriteriaId":"E99FB859-D023-4B2B-A709-05E83A46E2A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.14:*:*:*:*:*:*:*","matchCriteriaId":"8D2EEBC7-1FAF-43E2-A124-C387C02D9E2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.15:*:*:*:*:*:*:*","matchCriteriaId":"95D242E4-D5EB-4785-A6EF-60B1E8E2B0EC"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.16:*:*:*:*:*:*:*","matchCriteriaId":"F6FEDD9C-FDF7-456A-B06C-0A4A4443991D"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.17:*:*:*:*:*:*:*","matchCriteriaId":"9245CDE2-B90A-4D47-BA20-A7869FF0A645"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.18:*:*:*:*:*:*:*","matchCriteriaId":"FB993E4D-E573-4495-97DE-465DDB2AA2DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.19:*:*:*:*:*:*:*","matchCriteriaId":"D0F106A3-63D5-4D07-9440-6628DBA78BE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.20:*:*:*:*:*:*:*","matchCriteriaId":"36CC03BC-DF34-43CD-90B0-27D23A1DD06A"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.21:*:*:*:*:*:*:*","matchCriteriaId":"16C90FEE-527E-47F5-8840-517A55163D8E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.22:*:*:*:*:*:*:*","matchCriteriaId":"0FAEA812-BB47-47A3-A975-B3B8D30DBA36"},{"vulnerable":true,"criteria":"cpe:2.3:a:openldap:openldap:2.4.23:*:*:*:*:*:*:*","matchCriteriaId":"5DE5D180-3972-40A0-ADAF-A4F3364D1381"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1024","Ordinal":"1","Title":"CVE-2011-1024","CVE":"CVE-2011-1024","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1024","Ordinal":"1","NoteData":"chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.","Type":"Description","Title":"CVE-2011-1024"},{"CveYear":"2011","CveId":"1024","Ordinal":"2","NoteData":"2011-03-19","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"1024","Ordinal":"3","NoteData":"2017-01-04","Type":"Other","Title":"Modified"}]}}}