CVE-2014-9713: Debian Linux

Medium severity, CVSS 4.0. EPSS: 1.9% chance of exploitation in the next 30 days.

The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Openldap Openldap: version 2.4.23 only; version 2.4.24 only; version 2.4.25 only; version 2.4.26 only; version 2.4.27 only; version 2.4.28 only; …

Published 2015-04-01. Last modified 2026-06-17.