CVE-2010-0296
glibc: Improper encoding of names with certain special character in utilities for writing to mtab table
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.
La macro "encode_name" en "misc/mntent_r.c" en la Librería C GNU (también conocida como glibc or libc6) v2.11.1 y anteriores, como la usada por "ncpmount" y "mount.cifs" no maneja correctamente los caracteres de "nueva línea" en los nombres de punto de montaje, que permite a usuarios locales provocar una denegación de servicio (corrupción de mtab) o posiblemente modificar las opciones de montado y ganar privilegios, a través de una petición de montaje manipulada
The industrial managed switch series 852 from WAGO is affected by multiple vulnerabilities such as old software components embedded in the firmware. Furthermore, hardcoded password hashes and credentials were also found by doing an automated scan with IoT Inspector.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-01-12 CVE Reserved
- 2010-06-01 CVE Published
- 2019-06-13 First Exploit
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (24)
URL | Tag | Source |
---|---|---|
http://frugalware.org/security/662 | X_refsource_confirm | |
http://packetstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2019/Jun/18 | Mailing List |
|
http://secunia.com/advisories/43830 | Third Party Advisory | |
http://secunia.com/advisories/46397 | Third Party Advisory | |
http://securitytracker.com/id?1024043 | Vdb Entry | |
http://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ab00f4eac8f4932211259ff87be83144f5211540 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/520102/100/0/threaded | Mailing List | |
http://www.vmware.com/security/advisories/VMSA-2011-0012.html | X_refsource_confirm | |
http://www.vupen.com/english/advisories/2011/0863 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/59240 | Vdb Entry | |
https://seclists.org/bugtraq/2019/Jun/14 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/153278 | 2019-06-13 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/39900 | 2023-02-13 | |
http://security.gentoo.org/glsa/glsa-201011-01.xml | 2023-02-13 | |
http://www.debian.org/security/2010/dsa-2058 | 2023-02-13 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2010:111 | 2023-02-13 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2010:112 | 2023-02-13 | |
http://www.redhat.com/support/errata/RHSA-2011-0412.html | 2023-02-13 | |
http://www.ubuntu.com/usn/USN-944-1 | 2023-02-13 | |
http://www.vupen.com/english/advisories/2010/1246 | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=559579 | 2012-02-13 | |
https://lists.opensuse.org/opensuse-security-announce/2010-10/msg00007.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2010-0296 | 2012-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | <= 2.11.1 Search vendor "Gnu" for product "Glibc" and version " <= 2.11.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0 Search vendor "Gnu" for product "Glibc" and version "2.0" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0.1 Search vendor "Gnu" for product "Glibc" and version "2.0.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0.2 Search vendor "Gnu" for product "Glibc" and version "2.0.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0.3 Search vendor "Gnu" for product "Glibc" and version "2.0.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0.4 Search vendor "Gnu" for product "Glibc" and version "2.0.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0.5 Search vendor "Gnu" for product "Glibc" and version "2.0.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.0.6 Search vendor "Gnu" for product "Glibc" and version "2.0.6" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.1 Search vendor "Gnu" for product "Glibc" and version "2.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.1.1 Search vendor "Gnu" for product "Glibc" and version "2.1.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.1.1.6 Search vendor "Gnu" for product "Glibc" and version "2.1.1.6" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.1.2 Search vendor "Gnu" for product "Glibc" and version "2.1.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.1.3 Search vendor "Gnu" for product "Glibc" and version "2.1.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.1.9 Search vendor "Gnu" for product "Glibc" and version "2.1.9" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.2 Search vendor "Gnu" for product "Glibc" and version "2.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.2.1 Search vendor "Gnu" for product "Glibc" and version "2.2.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.2.2 Search vendor "Gnu" for product "Glibc" and version "2.2.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.2.3 Search vendor "Gnu" for product "Glibc" and version "2.2.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.2.4 Search vendor "Gnu" for product "Glibc" and version "2.2.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.2.5 Search vendor "Gnu" for product "Glibc" and version "2.2.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3 Search vendor "Gnu" for product "Glibc" and version "2.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.1 Search vendor "Gnu" for product "Glibc" and version "2.3.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.2 Search vendor "Gnu" for product "Glibc" and version "2.3.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.3 Search vendor "Gnu" for product "Glibc" and version "2.3.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.4 Search vendor "Gnu" for product "Glibc" and version "2.3.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.5 Search vendor "Gnu" for product "Glibc" and version "2.3.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.6 Search vendor "Gnu" for product "Glibc" and version "2.3.6" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.3.10 Search vendor "Gnu" for product "Glibc" and version "2.3.10" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.4 Search vendor "Gnu" for product "Glibc" and version "2.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.5 Search vendor "Gnu" for product "Glibc" and version "2.5" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.5.1 Search vendor "Gnu" for product "Glibc" and version "2.5.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.6 Search vendor "Gnu" for product "Glibc" and version "2.6" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.6.1 Search vendor "Gnu" for product "Glibc" and version "2.6.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.7 Search vendor "Gnu" for product "Glibc" and version "2.7" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.8 Search vendor "Gnu" for product "Glibc" and version "2.8" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.9 Search vendor "Gnu" for product "Glibc" and version "2.9" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.10 Search vendor "Gnu" for product "Glibc" and version "2.10" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.10.1 Search vendor "Gnu" for product "Glibc" and version "2.10.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Glibc Search vendor "Gnu" for product "Glibc" | 2.11 Search vendor "Gnu" for product "Glibc" and version "2.11" | - |
Affected
|