cbcvebase.
CVE-2010-0015
published 2010-01-14

CVE-2010-0015: nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.10.2-4 (bookworm)glibc 2.10.2-4 (bookworm)
gnuglibc
gnuglibc
gnuglibc>= 0 < 2.10.2-42.10.2-4
gnuglibc>= 0 < 2.10.2-42.10.2-4
gnuglibc>= 0 < 2.10.2-42.10.2-4
gnuglibc>= 0 < 2.10.2-42.10.2-4

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH