PT-2010-1045 · Linux+1 · Linux-Pam+1

Sebastian Krahmer

·

Published

2010-11-16

·

Updated

2019-01-03

·

CVE-2010-4708

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux-PAM versions 1.1.2 and earlier pam-devel-1.1.1 pam-debuginfo-1.1.1 pam-1.1.1
Description The issue allows local users to potentially run programs with an unintended environment by executing a program that relies on the pam env PAM check. This could lead to a disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out locally.
Recommendations For Linux-PAM versions 1.1.2 and earlier, consider updating to a version later than 1.1.2 to resolve the issue. For pam-devel-1.1.1, pam-debuginfo-1.1.1, and pam-1.1.1, update to a version later than 1.1.1 to mitigate the risk. As a temporary workaround, consider restricting access to the pam env module until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06022
BDU:2015-06023
BDU:2015-06025
CVE-2010-4708
RHSA-2010:0891
RHSA-2010_0891

Affected Products

Linux-Pam
Red Hat