![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-3209 |
Description: | The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file. |
Test IDs: | 1.3.6.1.4.1.25623.1.1.10.2014.0212 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-3209 67200 http://www.securityfocus.com/bid/67200 [oss-security] 20140503 ldns-keygen creates private key world readable http://www.openwall.com/lists/oss-security/2014/05/03/2 [oss-security] 20140504 Re: ldns-keygen creates private key world readable http://www.openwall.com/lists/oss-security/2014/05/05/4 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746758 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746758 https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=573 https://www.nlnetlabs.nl/bugs-script/show_bug.cgi?id=573 |