CVE-2010-0015

NameCVE-2010-0015
Descriptionnis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1973-1
Debian Bugs560333

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glibc (PTS)buster2.28-10+deb10u1fixed
buster (security)2.28-10+deb10u2fixed
bullseye2.31-13+deb11u6fixed
bullseye (security)2.31-13+deb11u7fixed
bookworm2.36-9+deb12u1fixed
bookworm (security)2.36-9+deb12u3fixed
trixie2.37-10fixed
sid2.37-11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
eglibcsource(unstable)2.10.2-4medium560333
glibcsourceetch2.3.6.ds1-13etch10DSA-1973-1
glibcsourcelenny2.7-18lenny2DSA-1973-1
glibcsource(unstable)2.10.2-4medium

Search for package or bug name: Reporting problems