Multiple vulnerabilities were found in OpenLDAP, a free implementation
of the Lightweight Directory Access Protocol.
Please carefully check whether you are affected by CVE-2014-9713: if you
are, you will need to manually upgrade your configuration! See below for
more details on this. Just upgrading the packages might not be enough!
Please note this is a Debian specific vulnerability.
The new package wonβt use the unsafe access control rule for new
databases, but existing configurations wonβt be automatically
modified. Administrators are incited to look at the README.Debian
file provided by the updated package if they need to fix the access
control rule.
Thanks to Ryan Tandy for preparing this update.
CPE | Name | Operator | Version |
---|---|---|---|
openldap | eq | 2.4.23-7 | |
openldap | eq | 2.4.23-7.1 | |
openldap | eq | 2.4.23-7.2 | |
openldap | eq | 2.4.23-7.3 |