V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2010-0015
DEB
LowConfirmedExploit available

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adj…

CVSS
3.3
Low
EPSS
0.02
p81
Published
2010-01-01
Updated
2010-01-01
Description

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

Tags · CWE
CWE-255
Affected products
Glibc
CVSS vector
AV:A/AC:L/Au:N/C:P/I:N/A:N
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: A
Adjacent Network (A)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.015 · p81
Known exploited (KEV)
No
Known exploits — Сканер-ВС
15274
exploitdb · https://www.exploit-db.com/exploits/15274
Enterprise
15304
exploitdb · https://www.exploit-db.com/exploits/15304
Enterprise
17120
exploitdb · https://www.exploit-db.com/exploits/17120
Enterprise
18105
exploitdb · https://www.exploit-db.com/exploits/18105
Enterprise
31550
exploitdb · https://www.exploit-db.com/exploits/31550
Enterprise
33230
exploitdb · https://www.exploit-db.com/exploits/33230
Enterprise
36404
exploitdb · https://www.exploit-db.com/exploits/36404
Enterprise
44024
exploitdb · https://www.exploit-db.com/exploits/44024
Enterprise
44025
exploitdb · https://www.exploit-db.com/exploits/44025
Enterprise
CVE-2010-3847
github-poc · https://github.com/magisterquis/cve-2010-3847
Enterprise
Affected software
ProductVendorStatus
eglibcTracked
glibcTracked
glibcTracked
glibc*Tracked