Description
The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-3227 | The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file. |
Ubuntu USN |
USN-3491-1 | ldns vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T10:35:56.989Z
Reserved: 2014-05-03T00:00:00.000Z
Link: CVE-2014-3209
No data.
Status : Modified
Published: 2014-11-16T01:59:03.163
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-3209
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN