---
title: "CVE-2010-3905\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-3905?format=md
keywords: index, follow
---

# CVE-2010-3905

Publication date 16 December 2010

Last updated 24 July 2024

---

Ubuntu priority

**High**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The password reset feature in the administrator interface for Eucalyptus
2.0.0 and 2.0.1 does not perform authentication, which allows remote
attackers to gain privileges by sending password reset requests for other
users.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| eucalyptus | 10.10 maverick | Fixed 2.0+bzr1241-0ubuntu4.1 |
| 10.04 LTS lucid | Not affected |
| 9.10 karmic | Not affected |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3905)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-3905)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-3905)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-3905)

### Related Ubuntu Security Notices (USN)

+ [USN-1033-1](https://usn.ubuntu.com/USN-1033-1)
+ Eucalyptus vulnerability
+ 16 December 2010

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2010-3905>
