CRITICAL🇵🇱 Wersja polska

CVE-2014-7210

CVSS 9.8v3.1pub. 2025-06-26upd. 2025-08-06

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.

🤖 AI Analysis
How it works

The maintainer scripts of the pdns-backend-mysql package grant the pdns database user excessively broad permissions to the MySQL database — broader than required for normal DNS server operation. This means that in case of compromise of the pdns user account or an application using these permissions, an attacker gains access to database resources beyond the necessary minimum. The issue affects only the MySQL backend; other backends are not vulnerable.

Impact

An attacker can gain unauthorized access to the MySQL database with excessive permissions, enabling reading, modification, or deletion of DNS data, and potentially other data stored in the database.

Mitigation & patch

The pdns package should be updated to version 3.3.1-1 or newer within the Debian distribution. It is also recommended to manually verify and restrict the MySQL pdns user permissions to the absolute minimum necessary (principle of least privilege). Details are available in the vendor references and Debian LTS announcement.

Who is affected

The pdns package (pdns-backend-mysql) in the Debian distribution in versions prior to 3.3.1-1. Other backends are not vulnerable.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Debian

    OS
    Debian
    7.0
  • Debian Pdns

    APP
    Debian
    < 3.3.1-1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki