First published: Thu Jan 14 2010(Updated: )
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library (glibc) | =2.7 | |
GNU C Library (glibc) | =2.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0015 is considered a high severity vulnerability due to its potential to allow remote attackers to obtain encrypted passwords.
To fix CVE-2010-0015, update the GNU C Library to a non-vulnerable version, specifically any version later than 2.10.2.
CVE-2010-0015 affects GNU C Library versions 2.7 and 2.10.2 as well as Embedded GLIBC.
CVE-2010-0015 allows remote attackers to obtain the encrypted passwords of NIS accounts through the getpwnam function.
CVE-2010-0015 was reported in January 2010.