pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends
are not affected.
References
| Link | Resource |
|---|---|
| https://lists.debian.org/debian-lts-announce/2016/05/msg00046.html | Vendor Advisory Mailing List |
| https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb246939264d7b05 | Patch |
Configurations
History
No history.
Information
Published : 2025-06-26 21:15
Updated : 2025-08-06 16:38
NVD link : CVE-2014-7210
Mitre link : CVE-2014-7210
CVE.ORG link : CVE-2014-7210
JSON object : View
Products Affected
debian
- debian_linux
- pdns
CWE
CWE-276
Incorrect Default Permissions
