CVE-2010-0826

EUVD-2010-0852
The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
piotr_roszatyckilibnss-db
2.2.3:pre1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libnss-db
bookworm
2.2.3pre1-8
fixed
bullseye
2.2.3pre1-6
fixed
lenny
no-dsa
sid
2.2.3pre1-10
fixed
squeeze
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libnss-db
dapper
ignored
hardy
Fixed 2.2.3pre1-3ubuntu1.8.04.2
released
intrepid
Fixed 2.2.3pre1-3ubuntu1.8.10.2
released
jaunty
Fixed 2.2.3pre1-3ubuntu3.9.04.2
released
karmic
Fixed 2.2.3pre1-3ubuntu3.9.10.2
released