Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2015-03471

Опубликовано: 14 янв. 2010
Источник: fstec
CVSS2: 7.5
EPSS Низкий

Описание

Множественные уязвимости пакета libc6-sparcv9 операционной системы Debian GNU/Linux, эксплуатация которых может привести к нарушению конфиденциальности, целостности и доступности защищаемой информации. Эксплуатация уязвимостей может быть осуществлена удаленно

Вендор

Сообщество свободного программного обеспечения

Наименование ПО

Debian GNU/Linux

Версия ПО

до 4 (Debian GNU/Linux)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,5)

Возможные меры по устранению уязвимости

Проблема может быть решена обновлением операционной системы до следующих версий пакетов в зависимости от архитектуры:
Debian GNU/Linux 4:
ppc:
libc6-prof - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libc6-ppc64 - 2.3.6.ds1-13etch10
libc6-dev-ppc64 - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
s390x:
libc6-dbg - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6-prof - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libc6-dev-s390x - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
libc6-s390x - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
i686:
libc6-prof - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libc6-xen - 2.3.6.ds1-13etch10
libc6-i686 - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
libc6-amd64 - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libc6-dev-amd64 - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
hppa:
libc6-udeb - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6-prof - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
sparc:
libc6-sparcv9b - 2.3.6.ds1-13etch10
libc6-sparc64 - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6-sparcv9 - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
libc6-dev-sparc64 - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libc6-prof - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
x86-64:
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libc6-prof - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libc6-dev-i386 - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libc6-i386 - 2.3.6.ds1-13etch10
ia64:
libc6.1-udeb - 2.3.6.ds1-13etch10
libc6.1-dev - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6.1-prof - 2.3.6.ds1-13etch10
libc6.1 - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libc6.1-dbg - 2.3.6.ds1-13etch10
libc6.1-pic - 2.3.6.ds1-13etch10
alpha:
libc6.1 - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libc6.1-udeb - 2.3.6.ds1-13etch10
libc6.1-prof - 2.3.6.ds1-13etch10
libc6.1-pic - 2.3.6.ds1-13etch10
libc6.1-dbg - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6.1-dev - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
noarch:
glibc-doc - 2.3.6.ds1-13etch10
locales - 2.3.6.ds1-13etch10
mipsel:
locales-all - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6-prof - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
arm:
libnss-dns-udeb - 2.3.6.ds1-13etch10
libc6-dbg - 2.3.6.ds1-13etch10
libc6 - 2.3.6.ds1-13etch10
libc6-pic - 2.3.6.ds1-13etch10
libc6-prof - 2.3.6.ds1-13etch10
libc6-dev - 2.3.6.ds1-13etch10
libc6-udeb - 2.3.6.ds1-13etch10
locales-all - 2.3.6.ds1-13etch10
libnss-files-udeb - 2.3.6.ds1-13etch10
nscd - 2.3.6.ds1-13etch10
Debian GNU/Linux 5:
ppc:
libc6-dbg - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
libc6-dev - 2.7-18lenny2
libc6-prof - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6 - 2.7-18lenny2
libc6-pic - 2.7-18lenny2
libc6-ppc64 - 2.7-18lenny2
locales-all - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6-dev-ppc64 - 2.7-18lenny2
s390x:
libc6-udeb - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6-prof - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6-dev-s390x - 2.7-18lenny2
libc6-s390x - 2.7-18lenny2
libc6-pic - 2.7-18lenny2
libc6-dev - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6 - 2.7-18lenny2
locales-all - 2.7-18lenny2
i686:
libc6-prof - 2.7-18lenny2
locales-all - 2.7-18lenny2
libc6-i686 - 2.7-18lenny2
libc6-dev-amd64 - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6-dev - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6-pic - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
libc6 - 2.7-18lenny2
libc6-xen - 2.7-18lenny2
libc6-amd64 - 2.7-18lenny2
hppa:
libc6-dev - 2.7-18lenny2
locales-all - 2.7-18lenny2
libc6 - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6-pic - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
libc6-prof - 2.7-18lenny2
sparc:
libc6-pic - 2.7-18lenny2
libc6 - 2.7-18lenny2
locales-all - 2.7-18lenny2
libc6-sparc64 - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6-sparcv9b - 2.7-18lenny2
libc6-dev - 2.7-18lenny2
libc6-prof - 2.7-18lenny2
nscd - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
libc6-dev-sparc64 - 2.7-18lenny2
x86-64:
libc6 - 2.7-18lenny2
libc6-dev - 2.7-18lenny2
libc6-i386 - 2.7-18lenny2
libc6-prof - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
locales-all - 2.7-18lenny2
nscd - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
libc6-pic - 2.7-18lenny2
libc6-dev-i386 - 2.7-18lenny2
armel:
locales-all - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
libc6-prof - 2.7-18lenny2
libc6 - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
nscd - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6-dev - 2.7-18lenny2
libc6-pic - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
alpha:
libc6.1-dbg - 2.7-18lenny2
libc6.1-pic - 2.7-18lenny2
libc6.1-prof - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6.1-udeb - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6.1-dev - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6.1 - 2.7-18lenny2
libc6.1-alphaev67 - 2.7-18lenny2
locales-all - 2.7-18lenny2
ia64:
libc6.1-dbg - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6.1-prof - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6.1 - 2.7-18lenny2
locales-all - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6.1-udeb - 2.7-18lenny2
libc6.1-pic - 2.7-18lenny2
libc6.1-dev - 2.7-18lenny2
mips:
libc6-dev-mips64 - 2.7-18lenny2
libc6-mips64 - 2.7-18lenny2
libc6 - 2.7-18lenny2
libc6-dbg - 2.7-18lenny2
nscd - 2.7-18lenny2
libc6-mipsn32 - 2.7-18lenny2
locales-all - 2.7-18lenny2
libnss-dns-udeb - 2.7-18lenny2
libc6-dev-mipsn32 - 2.7-18lenny2
libnss-files-udeb - 2.7-18lenny2
libc6-udeb - 2.7-18lenny2
libc6-pic -

Статус уязвимости

Потенциальная уязвимость

Наличие эксплойта

Данные уточняются

Информация об устранении

Информация об устранении отсутствует

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 81%
0.01817
Низкий

7.5 High

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

redhat
почти 16 лет назад

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

nvd
почти 16 лет назад

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

debian
почти 16 лет назад

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 an ...

github
больше 3 лет назад

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

EPSS

Процентиль: 81%
0.01817
Низкий

7.5 High

CVSS2