CVE-2014-7210

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:debian:pdns:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

History

06 Aug 2025, 16:38

Type Values Removed Values Added
References () https://lists.debian.org/debian-lts-announce/2016/05/msg00046.html - () https://lists.debian.org/debian-lts-announce/2016/05/msg00046.html - Vendor Advisory, Mailing List
References () https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb246939264d7b05 - () https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb246939264d7b05 - Patch
CPE cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:debian:pdns:*:*:*:*:*:*:*:*
First Time Debian pdns
Debian
Debian debian Linux

27 Jun 2025, 19:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) El paquete específico de pdns, tal como se incluye en Debian en versiones anteriores a la 3.3.1-1, crea un usuario MySQL con demasiados privilegios. Se descubrió que los scripts de mantenimiento de pdns-backend-mysql otorgan permisos de base de datos demasiado amplios al usuario pdns. Los demás backends no se ven afectados.

26 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-26 21:15

Updated : 2025-08-06 16:38


NVD link : CVE-2014-7210

Mitre link : CVE-2014-7210

CVE.ORG link : CVE-2014-7210


JSON object : View

Products Affected

debian

  • pdns
  • debian_linux
CWE
CWE-276

Incorrect Default Permissions