Back

HIGH

glibc NIS password hash disclosure

Published Jan 14, 2010

Description

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

Affected products

Remediation

Red Hat statement

The Red Hat Security Response Team has rated this issue as having low security impact. We do not currently plan to address this flaw on Red Hat Enterprise Linux 4 and 5. This issue does not affect Red Hat Enterprise Linux 6.

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 14, 2010
Updated Aug 7, 2024
Reserved Dec 14, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 10, 2009
ENISA EUVD
Assigner redhat
Published Jan 14, 2010
Updated Aug 7, 2024
Exploited since n/a
EUVD-2010-0047