PT-2013-2844 · Canonical · Pam-Xdg-Support
Sebastian Krzyszkowiak
+1
·
Published
2013-03-21
·
Updated
2017-08-29
·
CVE-2013-1052
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
pam-xdg-support as used in Ubuntu 12.10
Description
The issue is related to the handling of the PATH environment variable by pam-xdg-support, allowing local users to gain privileges through unspecified vectors related to sudo.
Recommendations
For Ubuntu 12.10, consider restricting the use of sudo until a proper fix is applied to pam-xdg-support to handle the PATH environment variable securely.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pam-Xdg-Support