CVE-2010-0015

NameCVE-2010-0015
Descriptionnis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1973-1
Debian Bugs560333

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glibc (PTS)bullseye (security), bullseye2.31-13+deb11u10fixed
bookworm, bookworm (security)2.36-9+deb12u7fixed
trixie2.39-4fixed
sid2.39-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
eglibcsource(unstable)2.10.2-4medium560333
glibcsourceetch2.3.6.ds1-13etch10DSA-1973-1
glibcsourcelenny2.7-18lenny2DSA-1973-1
glibcsource(unstable)2.10.2-4medium

Search for package or bug name: Reporting problems