Show plain JSON{"id": "CVE-2010-0015", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2010-01-14T18:30:00.577", "references": [{"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333", "source": "secalert@redhat.com"}, {"url": "http://marc.info/?l=oss-security&m=126320356003425&w=2", "source": "secalert@redhat.com"}, {"url": "http://marc.info/?l=oss-security&m=126320570505651&w=2", "source": "secalert@redhat.com"}, {"url": "http://sourceware.org/bugzilla/show_bug.cgi?id=11134", "source": "secalert@redhat.com"}, {"url": "http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markup", "source": "secalert@redhat.com"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:111", "source": "secalert@redhat.com"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:112", "source": "secalert@redhat.com"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/07/3", "source": "secalert@redhat.com"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/08/1", "source": "secalert@redhat.com"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/08/2", "source": "secalert@redhat.com"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/11/6", "source": "secalert@redhat.com"}, {"url": "https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html", "source": "secalert@redhat.com"}, {"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://marc.info/?l=oss-security&m=126320356003425&w=2", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://marc.info/?l=oss-security&m=126320570505651&w=2", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://sourceware.org/bugzilla/show_bug.cgi?id=11134", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&view=markup", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:111", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2010:112", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/07/3", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/08/1", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/08/2", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.openwall.com/lists/oss-security/2010/01/11/6", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-255"}]}], "descriptions": [{"lang": "en", "value": "nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function."}, {"lang": "es", "value": "nis/nss_nis/nis-pwd.c en GNU C Library (tambi\u00e9n conocido como glibc o libc6) v2.7 y Embedded GLIBC (EGLIBC) v2.10.2, a\u00f1ade informaci\u00f3n desde el mapa passwd.adjunct.byname a las entradas en el mapa \"passwd\", lo que permite a atacantes remotos obtener las contrase\u00f1as encriptadas de las cuentas NIS llamando a la funci\u00f3n getpwam."}], "lastModified": "2025-04-09T00:30:58.490", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:gnu:glibc:2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D41ABE25-DECD-4068-93DA-0B85281FD93A"}, {"criteria": "cpe:2.3:a:gnu:glibc:2.10.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A93600D-7271-4AF5-8133-C6AA5BC8543F"}], "operator": "OR"}]}], "sourceIdentifier": "secalert@redhat.com"}