CVE-2014-3209

The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nlnetlabs:ldns:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.9:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.10:*:*:*:*:*:*:*
cpe:2.3:a:nlnetlabs:ldns:1.6.11:*:*:*:*:*:*:*

History

21 Nov 2024, 02:07

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2014/05/03/2 - () http://www.openwall.com/lists/oss-security/2014/05/03/2 -
References () http://www.openwall.com/lists/oss-security/2014/05/05/4 - () http://www.openwall.com/lists/oss-security/2014/05/05/4 -
References () http://www.securityfocus.com/bid/67200 - () http://www.securityfocus.com/bid/67200 -
References () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746758 - () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746758 -
References () https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=573 - () https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=573 -

Information

Published : 2014-11-16 01:59

Updated : 2024-11-21 02:07


NVD link : CVE-2014-3209

Mitre link : CVE-2014-3209

CVE.ORG link : CVE-2014-3209


JSON object : View

Products Affected

nlnetlabs

  • ldns
CWE
CWE-264

Permissions, Privileges, and Access Controls