Vulnerability Name: | CVE-2010-0826 (CCN-57497) | ||||||||||||||||||||||||||||
Assigned: | 2010-04-01 | ||||||||||||||||||||||||||||
Published: | 2010-04-01 | ||||||||||||||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||||||||||||||
Summary: | The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N) 1.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
1.7 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
1.5 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:UR)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-0826 Source: CONFIRM Type: UNKNOWN http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 Source: FEDORA Type: UNKNOWN FEDORA-2010-6203 Source: CCN Type: VMSA-2010-0015 VMware ESX third party updates for Service Console Source: CCN Type: RHSA-2010-0347 Moderate: nss_db security update Source: SECUNIA Type: Vendor Advisory 39165 Source: CCN Type: SA41618 VMware ESX Server Service Console Multiple Vulnerabilities Source: CCN Type: GNU C Library Web page GNU C Library Source: MANDRIVA Type: UNKNOWN MDVSA-2010:077 Source: CCN Type: OSVDB ID: 63638 Berkeley DB NSS module (libnss-db) DB_CONFIG setgid / setuid Application Symlink Local Information Disclosure Source: BID Type: UNKNOWN 39132 Source: CCN Type: BID-39132 GNU libnss_db Local Information Disclosure Vulnerability Source: CCN Type: USN-922-1 libnss-db vulnerability Source: UBUNTU Type: UNKNOWN USN-922-1 Source: VUPEN Type: Vendor Advisory ADV-2010-0776 Source: VUPEN Type: UNKNOWN ADV-2010-0841 Source: VUPEN Type: UNKNOWN ADV-2010-0903 Source: CCN Type: Ubuntu Bug #531976 libnss_db reads a DB_CONFIG file in the current directory Source: CONFIRM Type: UNKNOWN https://bugs.launchpad.net/ubuntu/+source/libnss-db/+bug/531976 Source: XF Type: UNKNOWN libnssdb-dbcnofig-info-disclosure(57497) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10727 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6681 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |