pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2016/05/msg00046.html | vendor advisory mailing list |
https://salsa.debian.org/debian/pdns/-/commit/f0de6b3583039bb63344fbd5eb246939264d7b05 | patch |