CVE-2011-1025
EPSS 7.3%
Description
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
How to fix CVE-2011-1025
To remediate CVE-2011-1025, upgrade the affected package to a fixed version below.
- Debian/openldap—upgrade to 2.4.25-1 or later
Is CVE-2011-1025 being exploited?
Moderate — EPSS is 7.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.4.25-1