CVE-2014-8182: Debian Linux

High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Openldap Openldap: version 2.4 only

Published 2020-01-02. Last modified 2026-06-17.