pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends
are not affected.
References
Link | Resource |
---|---|
https://lists.debian.org/debian-lts-announce/2016/05/msg00046.html | Vendor Advisory Mailing List |
https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb246939264d7b05 | Patch |
Configurations
History
06 Aug 2025, 16:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.debian.org/debian-lts-announce/2016/05/msg00046.html - Vendor Advisory, Mailing List | |
References | () https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb246939264d7b05 - Patch | |
CPE | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* cpe:2.3:a:debian:pdns:*:*:*:*:*:*:*:* |
|
First Time |
Debian pdns
Debian Debian debian Linux |
27 Jun 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-276 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
26 Jun 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-26 21:15
Updated : 2025-08-06 16:38
NVD link : CVE-2014-7210
Mitre link : CVE-2014-7210
CVE.ORG link : CVE-2014-7210
JSON object : View
Products Affected
debian
- pdns
- debian_linux
CWE
CWE-276
Incorrect Default Permissions