pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.
The maintainer scripts of the pdns-backend-mysql package grant the pdns database user excessively broad permissions to the MySQL database — broader than required for normal DNS server operation. This means that in case of compromise of the pdns user account or an application using these permissions, an attacker gains access to database resources beyond the necessary minimum. The issue affects only the MySQL backend; other backends are not vulnerable.
An attacker can gain unauthorized access to the MySQL database with excessive permissions, enabling reading, modification, or deletion of DNS data, and potentially other data stored in the database.
The pdns package should be updated to version 3.3.1-1 or newer within the Debian distribution. It is also recommended to manually verify and restrict the MySQL pdns user permissions to the absolute minimum necessary (principle of least privilege). Details are available in the vendor references and Debian LTS announcement.
The pdns package (pdns-backend-mysql) in the Debian distribution in versions prior to 3.3.1-1. Other backends are not vulnerable.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDebian
OSDebian7.0Debian Pdns
APPDebian< 3.3.1-1
Related vulnerabilities
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki