CVE-2010-0015
Published Jan 14, 2010
Last updated 8 years ago
Overview
- Description
- nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-255
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gnu:glibc:2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D41ABE25-DECD-4068-93DA-0B85281FD93A" }, { "criteria": "cpe:2.3:a:gnu:glibc:2.10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A93600D-7271-4AF5-8133-C6AA5BC8543F" } ], "operator": "OR" } ] } ]