CVE-2014-9713
published 2015-04-01CVE-2014-9713: The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions…
PriorityP421medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.90%
77.4th percentile
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openldap | < openldap 2.4.40-2 (bookworm) | openldap 2.4.40-2 (bookworm) |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | — | — |
| openldap | openldap | >= 0 < 2.4.40-2 | 2.4.40-2 |
| openldap | openldap | >= 0 < 2.4.40-2 | 2.4.40-2 |
| openldap | openldap | >= 0 < 2.4.40-2 | 2.4.40-2 |
| openldap | openldap | >= 0 < 2.4.40-2 | 2.4.40-2 |
| openldap | openldap | >= 0 < 2.4.31-1+nmu2ubuntu8.2 | 2.4.31-1+nmu2ubuntu8.2 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jf44-946v-6x9w: The default slapd configuration in the Debian openldap package 2
ghsa_unreviewed·2022-05-17
CVE-2014-9713 [MEDIUM] GHSA-jf44-946v-6x9w: The default slapd configuration in the Debian openldap package 2
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
OSV
openldap vulnerabilities
osv·2015-09-16·CVSS 4.0
CVE-2015-6908 [MEDIUM] openldap vulnerabilities
openldap vulnerabilities
Denis Andzakovic discovered that OpenLDAP incorrectly handled certain BER
data. A remote attacker could possibly use this issue to cause OpenLDAP to
crash, resulting in a denial of service. (CVE-2015-6908)
Dietrich Clauss discovered that the OpenLDAP package incorrectly shipped
with a potentially unsafe default access control configuration. Depending
on how the database is configure, this may allow users to impersonate
others by modifying attributes such as their Unix user and group numbers.
(CVE-2014-9713)
OSV
CVE-2014-9713: The default slapd configuration in the Debian openldap package 2
osv·2015-04-01·CVSS 4.0
CVE-2014-9713 [MEDIUM] CVE-2014-9713: The default slapd configuration in the Debian openldap package 2
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
Ubuntu
OpenLDAP vulnerabilities
vendor_ubuntu·2015-09-16·CVSS 4.0
CVE-2014-9713 [MEDIUM] OpenLDAP vulnerabilities
Title: OpenLDAP vulnerabilities
Summary: Several security issues were fixed in OpenLDAP.
Denis Andzakovic discovered that OpenLDAP incorrectly handled certain BER
data. A remote attacker could possibly use this issue to cause OpenLDAP to
crash, resulting in a denial of service. (CVE-2015-6908)
Dietrich Clauss discovered that the OpenLDAP package incorrectly shipped
with a potentially unsafe default access control configuration. Depending
on how the database is configure, this may allow users to impersonate
others by modifying attributes such as their Unix user and group numbers.
(CVE-2014-9713)
Instructions: In general, a standard system update will make all the necessary changes.
For existing installations, access rules that begin with "to *" need to be
manually adjusted to remove an
Debian
CVE-2014-9713: openldap - The default slapd configuration in the Debian openldap package 2.4.23-3 through ...
vendor_debian·2014·CVSS 4.0
CVE-2014-9713 [MEDIUM] CVE-2014-9713: openldap - The default slapd configuration in the Debian openldap package 2.4.23-3 through ...
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.4.40-2)
bullseye: resolved (fixed in 2.4.40-2)
forky: resolved (fixed in 2.4.40-2)
sid: resolved (fixed in 2.4.40-2)
trixie: resolved (fixed in 2.4.40-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2015/dsa-3209http://www.openwall.com/lists/oss-security/2015/03/29/2http://www.securityfocus.com/bid/73217http://www.ubuntu.com/usn/USN-2742-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761406http://www.debian.org/security/2015/dsa-3209http://www.openwall.com/lists/oss-security/2015/03/29/2http://www.securityfocus.com/bid/73217http://www.ubuntu.com/usn/USN-2742-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761406
2015-04-01
Published