nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glibc | Jul 30, 2024 | Jan 14, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 10, 2009 |
| Suse | — | Upgrade glibc-dceextUpgrade glibc-dceext-64bitUpgrade glibc-locale-32bitUpgrade glibc-devel-64bitUpgrade nscdUpgrade glibc-64bitUpgrade glibc-infoUpgrade glibc-profile-32bitUpgrade glibc-profileUpgrade glibc-obsoleteUpgrade glibc-devel-32bitUpgrade glibc-develUpgrade glibc-x86Upgrade sap-aio-releaseUpgrade glibc-locale-x86Upgrade glibc-localeUpgrade glibcUpgrade glibc-32bitUpgrade glibc-profile-x86Upgrade glibc-dceext-32bitUpgrade glibc-dceext-x86Upgrade glibc-htmlUpgrade glibc-locale-64bitUpgrade glibc-profile-64bitUpgrade glibc-i18ndata | Dec 12, 2013 | Jan 14, 2010 |
| Ubuntu | — | Upgrade libc6Upgrade libc-bin | Nov 8, 2024 | Jan 14, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub