CVE-2010-0015
published 2010-01-14CVE-2010-0015: nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.07%
86.2th percentile
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.10.2-4 (bookworm) | glibc 2.10.2-4 (bookworm) |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | >= 0 < 2.10.2-4 | 2.10.2-4 |
| gnu | glibc | >= 0 < 2.10.2-4 | 2.10.2-4 |
| gnu | glibc | >= 0 < 2.10.2-4 | 2.10.2-4 |
| gnu | glibc | >= 0 < 2.10.2-4 | 2.10.2-4 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-42jr-443g-g58q: nis/nss_nis/nis-pwd
ghsa_unreviewed·2022-05-02
CVE-2010-0015 [HIGH] GHSA-42jr-443g-g58q: nis/nss_nis/nis-pwd
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
OSV
CVE-2010-0015: nis/nss_nis/nis-pwd
osv·2010-01-14·CVSS 7.5
CVE-2010-0015 [HIGH] CVE-2010-0015: nis/nss_nis/nis-pwd
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2012-03-09·CVSS 6.8
CVE-2009-5029 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Multiple vulnerabilities were discovered and fixed in the GNU C Library.
It was discovered that the GNU C Library did not properly handle
integer overflows in the timezone handling code. An attacker could use
this to possibly execute arbitrary code by convincing an application
to load a maliciously constructed tzfile. (CVE-2009-5029)
It was discovered that the GNU C Library did not properly handle
passwd.adjunct.byname map entries in the Network Information Service
(NIS) code in the name service caching daemon (nscd). An attacker
could use this to obtain the encrypted passwords of NIS accounts.
This issue only affected Ubuntu 8.04 LTS. (CVE-2010-0015)
Chris Evans reported that the GNU C Library did not properly
calculate the amount of memor
Debian
CVE-2010-0015: glibc - nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded...
vendor_debian·2010·CVSS 7.5
CVE-2010-0015 [HIGH] CVE-2010-0015: glibc - nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded...
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Scope: local
bookworm: resolved (fixed in 2.10.2-4)
bullseye: resolved (fixed in 2.10.2-4)
forky: resolved (fixed in 2.10.2-4)
sid: resolved (fixed in 2.10.2-4)
trixie: resolved (fixed in 2.10.2-4)
Red Hat
glibc NIS password hash disclosure
vendor_redhat·2009-12-10·CVSS 7.5
CVE-2010-0015 [HIGH] glibc NIS password hash disclosure
glibc NIS password hash disclosure
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. We do not currently plan to address this flaw on Red Hat Enterprise Linux 4 and 5. This issue does not affect Red Hat Enterprise Linux 6.
Package: glibc (Red Hat Enterprise Linux 4) - Affected
Package: glibc (Red Hat Enterprise Linux 5) - Affected
Package: glibc (Red Hat Enterprise Linux 6) - Affected
Suricata
GPL MISC CVS invalid directory response
suricata·2010-09-23
CVE-2003-0015 GPL MISC CVS invalid directory response
GPL MISC CVS invalid directory response
Rule: alert tcp $HOME_NET 2401 -> $EXTERNAL_NET any (msg:"GPL MISC CVS invalid directory response"; flow:established,to_client; content:"E protocol error|3A| invalid directory syntax in"; reference:bugtraq,6650; reference:cve,2003-0015; classtype:misc-attack; sid:2102011; rev:6; metadata:created_at 2010_09_23, cve CVE_2003_0015, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL MISC CVS double free exploit attempt response
suricata·2010-09-23
CVE-2003-0015 GPL MISC CVS double free exploit attempt response
GPL MISC CVS double free exploit attempt response
Rule: alert tcp $HOME_NET 2401 -> $EXTERNAL_NET any (msg:"GPL MISC CVS double free exploit attempt response"; flow:established,to_client; content:"free|28 29 3A| warning|3A| chunk is already free"; reference:bugtraq,6650; reference:cve,2003-0015; classtype:misc-attack; sid:2102010; rev:6; metadata:created_at 2010_09_23, cve CVE_2003_0015, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
suricata·2010-07-30
CVE-2007-0015 ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Apple Quicktime RTSP Overflow (2)"; flow:established,to_client; file.data; content:"|27|rtsp|3a|//"; nocase; isdataat:400,relative; content:!"|0a|"; within:400; content:!"|27|"; within:400; reference:cve,2007-0015; reference:bugtraq,21829; classtype:attempted-admin; sid:2003327; rev:11; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2007_0015, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_11;)
Suricata
ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
suricata·2010-07-30
CVE-2007-0015 ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Apple Quicktime RTSP Overflow (1)"; flow:established,to_client; file.data; content:"|22|rtsp|3a|//"; fast_pattern; nocase; isdataat:400,relative; content:!"|0a|"; within:400; content:!"|22|"; within:400; reference:cve,2007-0015; reference:bugtraq,21829; classtype:attempted-admin; sid:2003326; rev:11; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, cve CVE_2007_0015, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_11;)
Exploit-DB
Apple QuickTime 7.1.3 - RTSP URI Buffer Overflow (Metasploit)
exploitdb·2010-05-04
CVE-2007-0015 Apple QuickTime 7.1.3 - RTSP URI Buffer Overflow (Metasploit)
Apple QuickTime 7.1.3 - RTSP URI Buffer Overflow (Metasploit)
---
##
# $Id: apple_quicktime_rtsp.rb 9220 2010-05-04 23:09:32Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 OperatingSystems::WINDOWS,
:javascript => true,
:rank => NormalRanking, # reliable memory corruption
:vuln_test => nil,
})
def initialize(info = {})
super(update_info(info,
'Name' => 'Apple QuickTime 7.1.3 RTSP URI Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow in Apple QuickTime
7.1.3. This module was inspired by MOAB-01-01-2007.
Exploit-DB
Microsoft DirectShow - 'msvidctl.dll' MPEG-2 Memory Corruption (MS09-032/MS09-037) (Metasploit)
exploitdb·2010-04-30
CVE-2008-0015 Microsoft DirectShow - 'msvidctl.dll' MPEG-2 Memory Corruption (MS09-032/MS09-037) (Metasploit)
Microsoft DirectShow - 'msvidctl.dll' MPEG-2 Memory Corruption (MS09-032/MS09-037) (Metasploit)
---
##
# $Id: msvidctl_mpeg2.rb 9179 2010-04-30 08:40:19Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
##
# msvidctl_mpeg2.rb
#
# Microsoft DirectShow (msvidctl.dll) MPEG-2 Memory Corruption exploit for the Metasploit Framework
#
# Tested successfully on the following platforms (fully patched 06/07/09):
# - Internet Explorer 6, Windows XP SP2
# - Internet Explorer 7, Windows XP SP3
#
# Original exploit was found in-the-wild used to preform drive-by attacks via compromised C
Bugzilla
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
bugzilla·2011-01-20·CVSS 5.0
CVE-2011-0015 [MEDIUM] CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
epel-5 tracking bug for tor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-1676
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046
---
Adding parent bug CVE-2010-0383
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046,557798
---
Adding parent bug 705192
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?
Bugzilla
CVE-2010-0015 glibc NIS password hash disclosure
bugzilla·2010-01-14·CVSS 7.5
CVE-2010-0015 [HIGH] CVE-2010-0015 glibc NIS password hash disclosure
CVE-2010-0015 glibc NIS password hash disclosure
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0015 to the following vulnerability:
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7
and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the
passwd.adjunct.byname map to entries in the passwd map, which allows
remote attackers to obtain the encrypted passwords of NIS accounts by
calling the getpwnam function.
http://sourceware.org/bugzilla/show_bug.cgi?id=11134
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333
http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markup
Discussion:
The upstream fix for this can be found here:
http://sourceware.org/git/?p=glibc.git;a=com
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333http://marc.info/?l=oss-security&m=126320356003425&w=2http://marc.info/?l=oss-security&m=126320570505651&w=2http://sourceware.org/bugzilla/show_bug.cgi?id=11134http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markuphttp://www.mandriva.com/security/advisories?name=MDVSA-2010:111http://www.mandriva.com/security/advisories?name=MDVSA-2010:112http://www.openwall.com/lists/oss-security/2010/01/07/3http://www.openwall.com/lists/oss-security/2010/01/08/1http://www.openwall.com/lists/oss-security/2010/01/08/2http://www.openwall.com/lists/oss-security/2010/01/11/6https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333http://marc.info/?l=oss-security&m=126320356003425&w=2http://marc.info/?l=oss-security&m=126320570505651&w=2http://sourceware.org/bugzilla/show_bug.cgi?id=11134http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markuphttp://www.mandriva.com/security/advisories?name=MDVSA-2010:111http://www.mandriva.com/security/advisories?name=MDVSA-2010:112http://www.openwall.com/lists/oss-security/2010/01/07/3http://www.openwall.com/lists/oss-security/2010/01/08/1http://www.openwall.com/lists/oss-security/2010/01/08/2http://www.openwall.com/lists/oss-security/2010/01/11/6https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html
2010-01-14
Published