CVE-2010-0834
Last modified
CVE-2010-0834 is a vulnerability of currently unknown severity. The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.. EPSS estimates a 2.71% chance of exploitation in the next 30 days.
Description
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu | Ubuntu Linux | 9.10 |
| Ubuntu | Ubuntu Linux | 10.04 |
References
- http://secunia.com/advisories/40889Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2015Vendor Advisory
- http://secunia.com/advisories/40889Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2015Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0834?
How severe is CVE-2010-0834?
How do I fix CVE-2010-0834?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-0828Cross-site scripting (XSS) vulnerability in action/Despam.py…
- CVE-2010-0829Multiple array index errors in set.c in dvipng 1.11 and 1.12…
- CVE-2010-0830Integer signedness error in the elf_get_dynamic_info functio…
- CVE-2010-0831Directory traversal vulnerability in the extract_jar functio…
- CVE-2010-0832pam_motd (aka the MOTD module) in libpam-modules before 1.1.…
- CVE-2010-0833The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 befo…
- CVE-2010-0835Unspecified vulnerability in the Wireless component in Oracl…
- CVE-2010-0836Unspecified vulnerability in the Oracle Knowledge Management…
- CVE-2010-0837Unspecified vulnerability in the Pack200 component in Oracle…
- CVE-2010-0838Unspecified vulnerability in the Java 2D component in Oracle…
- CVE-2010-0839Unspecified vulnerability in the Sound component in Oracle J…
- CVE-2010-0840Unspecified vulnerability in the Java Runtime Environment co…9.8
Are you affected by CVE-2010-0834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
