CVE-2014-3209

NameCVE-2014-3209
DescriptionThe ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs746758

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ldns (PTS)buster1.7.0-4fixed
bullseye1.7.1-2fixed
trixie, bookworm1.8.3-1fixed
sid1.8.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ldnssourcewheezy1.6.13-1+deb7u1
ldnssource(unstable)1.6.17-4low746758

Notes

[squeeze] - ldns <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems