CVE-2010-0015: High severity gnu c library vulnerability
nis/nssnis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0015?
CVE-2010-0015 is considered a high severity vulnerability due to its potential to allow remote attackers to obtain encrypted passwords.
How do I fix CVE-2010-0015?
To fix CVE-2010-0015, update the GNU C Library to a non-vulnerable version, specifically any version later than 2.10.2.
What systems are affected by CVE-2010-0015?
CVE-2010-0015 affects GNU C Library versions 2.7 and 2.10.2 as well as Embedded GLIBC.
What impact does CVE-2010-0015 have on NIS accounts?
CVE-2010-0015 allows remote attackers to obtain the encrypted passwords of NIS accounts through the getpwnam function.
When was CVE-2010-0015 discovered?
CVE-2010-0015 was reported in January 2010.