PT-2010-1044 · Linux+1 · Linux-Pam+4

Publicado

2010-11-01

·

Atualizado

2019-01-03

·

CVE-2010-4707

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux-PAM versions 1.1.2 and earlier pam-devel-1.1.1 pam-debuginfo-1.1.1 pam-1.1.1
Description The issue is related to the pam xauth module in Linux-PAM, specifically the check acl function, which does not verify that a certain ACL file is a regular file. This might allow local users to cause a denial of service via a special file. Additionally, there are multiple vulnerabilities in the pam-devel, pam-debuginfo, and pam packages in Red Hat Enterprise Linux, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited locally.
Recommendations For Linux-PAM versions 1.1.2 and earlier, consider updating to a newer version to mitigate the risk. For pam-devel-1.1.1, pam-debuginfo-1.1.1, and pam-1.1.1, restrict access to the vulnerable modules to minimize the risk of exploitation. As a temporary workaround, consider disabling the check acl function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06022
BDU:2015-06023
BDU:2015-06025
CVE-2010-4707
RHSA-2010:0819
RHSA-2010:0891
RHSA-2010_0819
RHSA-2010_0891

Produtos afetados

Linux-Pam
Red Hat
Pam
Ipa-Debuginfo
Pam-Devel