CVE-2014-7210: Critical severity PowerDNS pdns vulnerability
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7210?
CVE-2014-7210 is categorized as a medium severity vulnerability due to excessive database privileges granted to the MySQL user by PowerDNS.
How do I fix CVE-2014-7210?
To fix CVE-2014-7210, it is essential to upgrade PowerDNS to version 3.3.1-1 or later to ensure proper database user permissions.
Which versions of PowerDNS are affected by CVE-2014-7210?
CVE-2014-7210 affects PowerDNS versions prior to 3.3.1-1 on Debian.
What are the implications of CVE-2014-7210?
The implications of CVE-2014-7210 include the risk of unauthorized access to the database due to overly permissive MySQL user privileges.
Is CVE-2014-7210 specific to any backend systems?
Yes, CVE-2014-7210 specifically affects the MySQL backend of PowerDNS and does not impact other backend systems.