CVE-2010-0834
published 2010-08-10CVE-2010-0834: The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks…
PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.71%
85.0th percentile
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | base-files | — | — |
| ubuntu | ubuntu_linux | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_debian9.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Dell Latitude 2110 vulnerability
vendor_ubuntu·2010-08-05
CVE-2010-0834 Dell Latitude 2110 vulnerability
Title: Dell Latitude 2110 vulnerability
Summary: Insecure Apt configuration on Dell Latitude 2110.
It was discovered that the Ubuntu image shipped on some Dell Latitude
2110 systems was accidentally configured to allow unauthenticated package
installations. A remote attacker intercepting network communications or
a malicious archive mirror server could exploit this to trick the user
into installing unsigned packages, resulting in arbitrary code execution
with root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2010-0834: base-files - The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubun...
vendor_debian·2010·CVSS 9.3
CVE-2010-0834 [CRITICAL] CVE-2010-0834: base-files - The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubun...
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-mr8q-567w-34vp: The base-files package before 5
ghsa_unreviewed·2022-05-02
CVE-2010-0834 [HIGH] CWE-287 GHSA-mr8q-567w-34vp: The base-files package before 5
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/40889http://www.securityfocus.com/bid/42280http://www.ubuntu.com/usn/usn-968-1http://www.vupen.com/english/advisories/2010/2015http://secunia.com/advisories/40889http://www.securityfocus.com/bid/42280http://www.ubuntu.com/usn/usn-968-1http://www.vupen.com/english/advisories/2010/2015
2010-08-10
Published