cbcvebase.
CVE-2010-0015
published 2010-01-14

CVE-2010-0015: nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to…

PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.07%
86.2th percentile
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.10.2-4 (bookworm)glibc 2.10.2-4 (bookworm)
gnuglibc
gnuglibc
gnuglibc>= 0 < 2.10.2-42.10.2-4
gnuglibc>= 0 < 2.10.2-42.10.2-4
gnuglibc>= 0 < 2.10.2-42.10.2-4
gnuglibc>= 0 < 2.10.2-42.10.2-4

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.