Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-0826
HistoryMar 31, 2010 - 12:00 a.m.

CVE-2010-0826

2010-03-3100:00:00
ubuntu.com
ubuntu.com
15

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db)
2.2.3pre1 reads the DB_CONFIG file in the current working directory, which
allows local users to obtain sensitive information via a symlink attack
involving a setgid or setuid application that uses this module.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchlibnss-db<Β 2.2.3pre1-3ubuntu1.8.04.2UNKNOWN
ubuntu8.10noarchlibnss-db<Β 2.2.3pre1-3ubuntu1.8.10.2UNKNOWN
ubuntu9.04noarchlibnss-db<Β 2.2.3pre1-3ubuntu3.9.04.2UNKNOWN
ubuntu9.10noarchlibnss-db<Β 2.2.3pre1-3ubuntu3.9.10.2UNKNOWN

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%