Lucene search

K
cve[email protected]CVE-2010-0015
HistoryJan 14, 2010 - 6:30 p.m.

CVE-2010-0015

2010-01-1418:30:00
CWE-255
web.nvd.nist.gov
44
nis
passwords
vulnerability
remote attack
glibc
libc6
eglibc
cve-2010-0015

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.023 Low

EPSS

Percentile

89.7%

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

Affected configurations

NVD
Node
gnuglibcMatch2.7
OR
gnuglibcMatch2.10.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.023 Low

EPSS

Percentile

89.7%