CVE-2010-0015 PUBLISHED CVSS 7.5 HIGH

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

EPSS 1.82% · 82.7th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
1.82%
82.7th percentile

Affected Products

VendorProductVersions
gnuglibc2.7, 2.10.2
n/an/an/a

Timeline

References

Open in Interactive Console →