CVE-2010-3905

Publication date 16 December 2010

Last updated 24 July 2024


Ubuntu priority

The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users.

Status

Package Ubuntu Release Status
eucalyptus 10.10 maverick
Fixed 2.0+bzr1241-0ubuntu4.1
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-1033-1
    • Eucalyptus vulnerability
    • 16 December 2010

Other references