CVE-2017-11501
Last modified
CVE-2017-11501 is a vulnerability of currently unknown severity. NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
NixOS 17.03 and earlier has an unintended default absence of SSL Certificate Validation for LDAP. The users.ldap NixOS module implements user authentication against LDAP servers via a PAM module. It was found that if TLS is enabled to connect to the LDAP server with users.ldap.useTLS, peer verification will be unconditionally disabled in /etc/ldap.conf.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nixos Project | Nixos | <= 17.03 |
References
- http://openwall.com/lists/oss-security/2017/07/20/1Mailing List, Mitigation, Patch, Third Party Advisory
- https://github.com/NixOS/nixpkgs/issues/27506Issue Tracking, Third Party Advisory
- http://openwall.com/lists/oss-security/2017/07/20/1Mailing List, Mitigation, Patch, Third Party Advisory
- https://github.com/NixOS/nixpkgs/issues/27506Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11501?
How severe is CVE-2017-11501?
How do I fix CVE-2017-11501?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11496Stack buffer overflow in hasplms in Gemalto ACC (Admin Contr…
- CVE-2017-11497Stack buffer overflow in hasplms in Gemalto ACC (Admin Contr…
- CVE-2017-11498Buffer overflow in hasplms in Gemalto ACC (Admin Control Cen…
- CVE-2017-11499Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 thro…
- CVE-2017-1150IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Se…
- CVE-2017-11500A directory traversal vulnerability exists in MetInfo 5.3.17…7.5
- CVE-2017-11502Technicolor DPC3928AD DOCSIS devices allow remote attackers …
- CVE-2017-11503PHPMailer 5.2.23 has XSS in the "From Email Address" and "To…
- CVE-2017-11505The ReadOneJNGImage function in coders/png.c in ImageMagick …
- CVE-2017-11506When linking a Nessus scanner or agent to Tenable.io or othe…
- CVE-2017-11507A cross site scripting (XSS) vulnerability exists in Check_M…
- CVE-2017-11508SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL…
Are you affected by CVE-2017-11501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
