PT-2010-1045 · Linux+1 · Linux-Pam+1

Sebastian Krahmer

·

Publicado

2010-11-16

·

Atualizado

2019-01-03

·

CVE-2010-4708

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux-PAM versions 1.1.2 and earlier pam-devel-1.1.1 pam-debuginfo-1.1.1 pam-1.1.1
Description The issue allows local users to potentially run programs with an unintended environment by executing a program that relies on the pam env PAM check. This could lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out locally.
Recommendations For Linux-PAM versions 1.1.2 and earlier, consider updating to a version later than 1.1.2 to resolve the issue. For pam-devel-1.1.1, pam-debuginfo-1.1.1, and pam-1.1.1, update to a version later than 1.1.1 to mitigate the risk. As a temporary workaround, consider restricting access to the pam env module until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-06022
BDU:2015-06023
BDU:2015-06025
CVE-2010-4708
RHSA-2010:0891
RHSA-2010_0891

Produtos afetados

Linux-Pam
Red Hat