Vulnerability Description
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Pdns | < 3.3.1-1 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2016/05/msg00046.htmlMailing ListVendor Advisory
- https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb24693926Patch
FAQ
What is CVE-2014-7210?
CVE-2014-7210 is a vulnerability with a CVSS score of 9.8 (CRITICAL). pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissio...
How severe is CVE-2014-7210?
CVE-2014-7210 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2014-7210?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Pdns, Debian Debian Linux.