CVE Vulnerabilities

CVE-2014-3209

Published: Nov 16, 2014 | Modified: Nov 17, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.

Affected Software

Name Vendor Start Version End Version
Ldns Nlnetlabs 1.6.0 (including) 1.6.0 (including)
Ldns Nlnetlabs 1.6.1 (including) 1.6.1 (including)
Ldns Nlnetlabs 1.6.2 (including) 1.6.2 (including)
Ldns Nlnetlabs 1.6.3 (including) 1.6.3 (including)
Ldns Nlnetlabs 1.6.4 (including) 1.6.4 (including)
Ldns Nlnetlabs 1.6.5 (including) 1.6.5 (including)
Ldns Nlnetlabs 1.6.6 (including) 1.6.6 (including)
Ldns Nlnetlabs 1.6.7 (including) 1.6.7 (including)
Ldns Nlnetlabs 1.6.8 (including) 1.6.8 (including)
Ldns Nlnetlabs 1.6.9 (including) 1.6.9 (including)
Ldns Nlnetlabs 1.6.10 (including) 1.6.10 (including)
Ldns Nlnetlabs 1.6.11 (including) 1.6.11 (including)
Ldns Ubuntu lucid *
Ldns Ubuntu precise *
Ldns Ubuntu quantal *
Ldns Ubuntu saucy *
Ldns Ubuntu trusty *
Ldns Ubuntu upstream *
Ldns Ubuntu utopic *
Ldns Ubuntu vivid *
Ldns Ubuntu wily *
Ldns Ubuntu yakkety *

References