PT-2016-7979 · Debian · Debian+1
Published
2025-06-26
·
Updated
2025-06-27
·
CVE-2014-7210
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
pdns versions prior to 3.3.1-1
Description:
The issue arises from the pdns package in Debian, where the MySQL user is created with excessive privileges. Specifically, the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. This issue does not affect other backends.
Recommendations:
For versions prior to 3.3.1-1, update to version 3.3.1-1 or later to resolve the issue. As a temporary workaround, consider restricting the database permissions for the pdns user to minimize the risk of exploitation.
Fix
LPE
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Pdns