Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0834

Опубликовано: 10 авг. 2010
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:o:ubuntu:ubuntu_linux:9.10:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:10.04:-:lts:*:*:*:*:*
cpe:2.3:h:dell:latitude_2110_netbook:*:*:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00508
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 15 лет назад

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.

debian
больше 15 лет назад

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before ...

github
больше 3 лет назад

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.

EPSS

Процентиль: 66%
0.00508
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-287