PT-2010-1043 · Linux Pam+1 · Pam+1

Tomas Hoger

+1

·

Published

2010-11-01

·

Updated

2024-06-15

·

CVE-2010-3853

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions pam versions prior to 1.1.3 Red Hat Enterprise Linux (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the pam package of Red Hat Enterprise Linux. These vulnerabilities can be exploited locally, potentially leading to breaches of confidentiality, integrity, and availability of protected information. The pam namespace module in Linux-PAM is specifically affected, where it uses the environment of the invoking application or service during execution of the namespace.init script. This might allow local users to gain privileges by running a setuid program that relies on the pam namespace PAM check.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pam namespace module until a patch is available. Avoid using setuid programs that rely on the pam namespace PAM check in vulnerable versions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06022
BDU:2015-06023
BDU:2015-06025
CVE-2010-3853
OPENSUSE-SU-2024:10405-1
RHSA-2010:0819
RHSA-2010:0891
RHSA-2010_0819
RHSA-2010_0891

Affected Products

Red Hat
Pam