Local Privilege Escalation Vulnerability in ldns Tool by NLnet Labs
CVE-2014-3209

Currently unrated

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
16 November 2014

What is CVE-2014-3209?

The ldns-keygen tool in ldns versions 1.6.x improperly sets file permissions for private keys due to using the current umask. This misconfiguration could allow local users to read private key files, potentially compromising the security of the system by exposing sensitive cryptographic information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.