#VU45413 Input validation error in linux-pam - CVE-2010-3435


| Updated: 2020-08-11

Vulnerability identifier: #VU45413

Vulnerability risk: Medium

CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2010-3435

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
linux-pam
Other software / Other software solutions

Vendor: git.kernel.org

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.

Mitigation
Install update from vendor's website.

Vulnerable software versions

linux-pam: 0.99.1.0 - 1.1.0


External links
https://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=06f882f30092a39a1db867c9744b2ca8d60e4ad6
https://lists.vmware.com/pipermail/security-announce/2011/000126.html
https://openwall.com/lists/oss-security/2010/09/21/3
https://openwall.com/lists/oss-security/2010/09/27/10
https://openwall.com/lists/oss-security/2010/09/27/4
https://openwall.com/lists/oss-security/2010/09/27/5
https://openwall.com/lists/oss-security/2010/09/27/7
https://openwall.com/lists/oss-security/2010/09/27/8
https://openwall.com/lists/oss-security/2010/10/25/2
https://secunia.com/advisories/49711
https://security.gentoo.org/glsa/glsa-201206-31.xml
https://www.mandriva.com/security/advisories?name=MDVSA-2010:220
https://www.openwall.com/lists/oss-security/2010/09/24/2
https://www.redhat.com/support/errata/RHSA-2010-0819.html
https://www.redhat.com/support/errata/RHSA-2010-0891.html
https://www.securityfocus.com/archive/1/516909/100/0/threaded
https://www.vmware.com/security/advisories/VMSA-2011-0004.html
https://www.vupen.com/english/advisories/2011/0606
https://bugzilla.redhat.com/show_bug.cgi?id=641335


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability