CVE-2014-3209
Summary
| CVE | CVE-2014-3209 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-11-16 01:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nlnetlabs | Ldns | 1.6.0 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.1 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.10 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.11 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.2 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.3 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.4 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.5 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.6 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.7 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.8 | All | All | All |
| Application | Nlnetlabs | Ldns | 1.6.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #746758 - ldnsutils: CVE-2014-3209: ldns-keygen creates private key world readable - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| ldns CVE-2014-3209 Local Insecure File Permissions Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bug 573 – CVE-2014-3209: ldns-keygen should create private key files with stricter permissions | af854a3a-2127-422b-91ae-364da2661108 | www.nlnetlabs.nl | |
| oss-security - Re: ldns-keygen creates private key world readable | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - ldns-keygen creates private key world readable | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.