Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-0015
HistoryJan 14, 2010 - 12:00 a.m.

CVE-2010-0015

2010-01-1400:00:00
ubuntu.com
ubuntu.com
13

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.023 Low

EPSS

Percentile

89.7%

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and
Embedded GLIBC (EGLIBC) 2.10.2 adds information from the
passwd.adjunct.byname map to entries in the passwd map, which allows remote
attackers to obtain the encrypted passwords of NIS accounts by calling the
getpwnam function.

Bugs

Notes

Author Note
mdeslaur in lucid+, in patch debian/patches/any/submitted-nis-shadow.diff
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchglibc< 2.7-10ubuntu8.1UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.023 Low

EPSS

Percentile

89.7%