glibc NIS password hash disclosure
Published Jan 14, 2010
7.5
HIGHCVSS 2.0
EPSS 3.13%
Description
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Affected products
No data.
No data.
Red Hat Enterprise Linux 4
glibc
Affected
Red Hat Enterprise Linux 5
glibc
Affected
Red Hat Enterprise Linux 6
glibc
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | glibc | Affected | n/a |
| Red Hat Enterprise Linux 5 | glibc | Affected | n/a |
| Red Hat Enterprise Linux 6 | glibc | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Security Response Team has rated this issue as having low security impact. We do not currently plan to address this flaw on Red Hat Enterprise Linux 4 and 5. This issue does not affect Red Hat Enterprise Linux 6.
References (17)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333 x_refsource_CONFIRM
- http://marc.info/?l=oss-security&m=126320356003425&w=2 mailing-listx_refsource_MLIST
- http://marc.info/?l=oss-security&m=126320570505651&w=2 mailing-listx_refsource_MLIST
- http://sourceware.org/bugzilla/show_bug.cgi?id=11134 x_refsource_MISC
- http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markup x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:111 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:112 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2010/01/07/3 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2010/01/08/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2010/01/08/2 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2010/01/11/6 mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2010-0015 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=555573 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0047 Advisory
- https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html vendor-advisoryx_refsource_SUSE
- https://nvd.nist.gov/vuln/detail/CVE-2010-0015
- https://www.cve.org/CVERecord?id=CVE-2010-0015
Change history (0)
No recorded changes yet.