PT-2016-7979 · Debian · Debian+1

CVE-2014-7210

·

Published

2025-06-26

·

Updated

2025-06-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: pdns versions prior to 3.3.1-1
Description: The issue arises from the pdns package in Debian, where the MySQL user is created with excessive privileges. Specifically, the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. This issue does not affect other backends.
Recommendations: For versions prior to 3.3.1-1, update to version 3.3.1-1 or later to resolve the issue. As a temporary workaround, consider restricting the database permissions for the pdns user to minimize the risk of exploitation.

Fix

LPE

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7210
DLA-492-1

Affected Products

Debian
Pdns