Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10152

Опубликовано: 28 мар. 2017
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

3.2.1-3.1~build0.18.04.1
cosmic

released

3.2.1-3.1~build0.18.10.1
devel

not-affected

3.2.1-3.1
disco

not-affected

3.2.1-3.1
esm-apps/bionic

released

3.2.1-3.1~build0.18.04.1
esm-apps/xenial

released

3.2.1-3.1~build0.16.04.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
precise

ignored

end of life
precise/esm

DNE

precise was needed

Показывать по

EPSS

Процентиль: 83%
0.01873
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
почти 10 лет назад

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.

CVSS3: 9.8
nvd
почти 9 лет назад

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.

CVSS3: 9.8
debian
почти 9 лет назад

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls ba ...

CVSS3: 9.8
github
больше 3 лет назад

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.

CVSS3: 9.8
fstec
почти 10 лет назад

Уязвимость функции read_config_file (lib/hesiod.c) демона для обеспечения доступа к базам данных DNS Hesiod, позволяющая нарушителю получить привилегии root

EPSS

Процентиль: 83%
0.01873
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3