CVE Vulnerabilities

CVE-2014-3209

Published: Nov 16, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.

Affected Software

NameVendorStart VersionEnd Version
LdnsNlnetlabs1.6.0 (including)1.6.0 (including)
LdnsNlnetlabs1.6.1 (including)1.6.1 (including)
LdnsNlnetlabs1.6.2 (including)1.6.2 (including)
LdnsNlnetlabs1.6.3 (including)1.6.3 (including)
LdnsNlnetlabs1.6.4 (including)1.6.4 (including)
LdnsNlnetlabs1.6.5 (including)1.6.5 (including)
LdnsNlnetlabs1.6.6 (including)1.6.6 (including)
LdnsNlnetlabs1.6.7 (including)1.6.7 (including)
LdnsNlnetlabs1.6.8 (including)1.6.8 (including)
LdnsNlnetlabs1.6.9 (including)1.6.9 (including)
LdnsNlnetlabs1.6.10 (including)1.6.10 (including)
LdnsNlnetlabs1.6.11 (including)1.6.11 (including)
LdnsUbuntulucid*
LdnsUbuntuprecise*
LdnsUbuntuquantal*
LdnsUbuntusaucy*
LdnsUbuntutrusty*
LdnsUbuntuupstream*
LdnsUbuntuutopic*
LdnsUbuntuvivid*
LdnsUbuntuwily*
LdnsUbuntuyakkety*

References