Improper User Privileges in PowerDNS MySQL Backend by Debian
CVE-2014-7210

9.8CRITICAL

Key Information:

Vendor

Debian

Status
Vendor
CVE Published:
26 June 2025

What is CVE-2014-7210?

A privilege escalation vulnerability exists in PowerDNS as packaged in Debian prior to version 3.3.1-1. This issue arises from the maintainer scripts granting the pdns user overly broad database permissions in the MySQL backend. This misconfiguration could potentially lead to unauthorized access to sensitive data and manipulation of the database, posing critical risks for affected systems.

Affected Version(s)

pdns 0 < 3.3.1-1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.