VYPR
Unrated severityNVD Advisory· Published Aug 10, 2010· Updated Apr 29, 2026

CVE-2010-0834

CVE-2010-0834

Description

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.

Affected products

2
  • Ubuntu/Linux2 versions
    cpe:2.3:o:ubuntu:ubuntu_linux:9.10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:ubuntu:ubuntu_linux:9.10:*:*:*:*:*:*:*
    • cpe:2.3:o:ubuntu:ubuntu_linux:10.04:-:lts:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.