Vulnerability Name: | CVE-2010-0834 (CCN-60957) | ||||||||
Assigned: | 2010-08-05 | ||||||||
Published: | 2010-08-05 | ||||||||
Updated: | 2010-08-10 | ||||||||
Summary: | The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0834 Source: CCN Type: SA40889 Ubuntu base-files Dell Latitude 2110 Unauthenticated Package Installation Source: SECUNIA Type: Vendor Advisory 40889 Source: CCN Type: OSVDB ID: 66963 Ubuntu base-files on Dell Latitude 2110 Unauthenticated Package Installation Source: BID Type: Patch 42280 Source: CCN Type: BID-42280 Ubuntu Dell Latitude 2110 Package Installation Security Bypass Vulnerability Source: CCN Type: Ubuntu Web site Ubuntu Source: CCN Type: USN-968-1 Dell Latitude 2110 vulnerability Source: UBUNTU Type: UNKNOWN USN-968-1 Source: VUPEN Type: Vendor Advisory ADV-2010-2015 Source: XF Type: UNKNOWN ubuntu-dell-security-bypass(60957) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |