Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-0833 | First vendor Publication | 2010-07-28 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0833 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-287 | Improper Authentication |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13389 | |||
Oval ID: | oval:org.mitre.oval:def:13389 | ||
Title: | USN-964-1 -- likewise-open vulnerability | ||
Description: | Matt Weatherford discovered that Likewise Open did not correctly check password expiration for the local-provider account. A local attacker could exploit this to log into a system they would otherwise not have access to. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-964-1 CVE-2010-0833 | Version: | 5 |
Platform(s): | Ubuntu 10.04 | Product(s): | likewise-open |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2010-08-06 | Name : Ubuntu Update for likewise-open regression USN-964-2 File : nvt/gb_ubuntu_USN_964_2.nasl |
2010-07-30 | Name : Ubuntu Update for likewise-open vulnerability USN-964-1 File : nvt/gb_ubuntu_USN_964_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
66806 | Likewise Open / Likewise-CIFS pam_lsass Library SetPassword Logic Expired Pas... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-08-04 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-964-2.nasl - Type : ACT_GATHER_INFO |
2010-07-27 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-964-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:08:00 |
|
2024-11-28 12:21:20 |
|
2021-05-04 12:11:14 |
|
2021-04-22 01:11:47 |
|
2020-05-23 00:25:23 |
|
2019-03-19 12:03:28 |
|
2018-10-11 00:19:48 |
|
2016-04-26 19:37:51 |
|
2014-02-17 10:54:13 |
|
2013-05-10 23:19:39 |
|