CVE-2010-0015
Published: 14 January 2010
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Notes
Author | Note |
---|---|
mdeslaur |
in lucid+, in patch debian/patches/any/submitted-nis-shadow.diff |
Priority
Status
Package | Release | Status |
---|---|---|
eglibc
Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Does not exist
|
|
intrepid |
Does not exist
|
|
jaunty |
Does not exist
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Not vulnerable
(2.11.1-0ubuntu7.8)
|
|
maverick |
Not vulnerable
(2.12.1-0ubuntu10.2)
|
|
natty |
Not vulnerable
(2.13-0ubuntu13)
|
|
oneiric |
Not vulnerable
(2.13-0ubuntu13)
|
|
upstream |
Released
(2.10.2-4)
|
|
Patches:
vendor: http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markup |
||
glibc
Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Released
(2.7-10ubuntu8.1)
|
|
intrepid |
Ignored
(end of life, was needed)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Does not exist
|
|
lucid |
Does not exist
|
|
maverick |
Does not exist
|
|
natty |
Does not exist
|
|
oneiric |
Does not exist
|
|
upstream |
Released
(2.10.2-4)
|