VulnerabilityModified
CVE-2014-3209
The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
LOW 2.1EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- nlnetlabs/ldns
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2014/05/03/2
- http://www.openwall.com/lists/oss-security/2014/05/05/4
- http://www.securityfocus.com/bid/67200
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746758
- https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=573
- http://www.openwall.com/lists/oss-security/2014/05/03/2
- http://www.openwall.com/lists/oss-security/2014/05/05/4
- http://www.securityfocus.com/bid/67200
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746758
- https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=573
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.