CVE Vulnerabilities

CVE-2014-9713

Published: Apr 01, 2015 | Modified: Dec 22, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the users permissions and other user attributes via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Openldap Openldap 2.4.23 (including) 2.4.23 (including)
Openldap Openldap 2.4.24 (including) 2.4.24 (including)
Openldap Openldap 2.4.25 (including) 2.4.25 (including)
Openldap Openldap 2.4.26 (including) 2.4.26 (including)
Openldap Openldap 2.4.27 (including) 2.4.27 (including)
Openldap Openldap 2.4.28 (including) 2.4.28 (including)
Openldap Openldap 2.4.29 (including) 2.4.29 (including)
Openldap Openldap 2.4.30 (including) 2.4.30 (including)
Openldap Openldap 2.4.31 (including) 2.4.31 (including)
Openldap Openldap 2.4.32 (including) 2.4.32 (including)
Openldap Openldap 2.4.33 (including) 2.4.33 (including)
Openldap Openldap 2.4.34 (including) 2.4.34 (including)
Openldap Openldap 2.4.35 (including) 2.4.35 (including)
Openldap Openldap 2.4.36 (including) 2.4.36 (including)
Openldap Openldap 2.4.37 (including) 2.4.37 (including)
Openldap Openldap 2.4.38 (including) 2.4.38 (including)
Openldap Openldap 2.4.39 (including) 2.4.39 (including)
Openldap Ubuntu devel *
Openldap Ubuntu precise *
Openldap Ubuntu trusty *
Openldap Ubuntu upstream *
Openldap Ubuntu utopic *
Openldap Ubuntu vivid *
Openldap Ubuntu vivid/stable-phone-overlay *
Openldap Ubuntu vivid/ubuntu-core *

References