Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 301761 - sys-libs/glibc: Password leak in nis/nss_nis/nis-pwd.c (CVE-2010-0015)
Summary: sys-libs/glibc: Password leak in nis/nss_nis/nis-pwd.c (CVE-2010-0015)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: A3 [invalid]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-01-21 19:21 UTC by cilly
Modified: 2010-04-25 12:03 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description cilly 2010-01-21 19:21:27 UTC
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
Comment 1 cilly 2010-01-21 19:32:16 UTC
This bug is present in glibc-2.10.2 to glibc-2.10.4.
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2010-03-01 12:51:37 UTC
Toolchain, can you please find out whether any version in the tree is affected by this? The CVE description is a bit unspecific with regard to version numbers. Also: Do we ship Embedded GLIBC?

I'm not sure if the statement from comment #1 is correct as I don't see what it relies on..
Comment 3 Tobias Heinlein (RETIRED) gentoo-dev 2010-03-01 12:55:13 UTC
CVE-2010-0015 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0015):
  nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7
  and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the
  passwd.adjunct.byname map to entries in the passwd map, which allows
  remote attackers to obtain the encrypted passwords of NIS accounts by
  calling the getpwnam function.

Comment 4 Mark Loeser (RETIRED) gentoo-dev 2010-03-01 21:52:25 UTC
We don't ship Embedded Glibc.  I can't find an approved patch by upstream for this issue yet either.

http://sourceware.org/bugzilla/show_bug.cgi?id=11134
Comment 5 SpanKY gentoo-dev 2010-04-25 07:20:20 UTC
nothing for us to do.  see the upstream bug report for more info.
Comment 6 Tobias Heinlein (RETIRED) gentoo-dev 2010-04-25 12:01:54 UTC
Security bug, reopening.
Comment 7 Tobias Heinlein (RETIRED) gentoo-dev 2010-04-25 12:03:04 UTC
(In reply to comment #5)
> nothing for us to do.  see the upstream bug report for more info.

Thanks for the input, I'm closing this invalid then.