TROYANOSYVIRUS
Volver a CVEs

CVE-2010-3435

N/A

Descripcion

The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado1/24/2011
Ultima modificacion4/29/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

linux-pam:linux-pam

Referencias

http://openwall.com/lists/oss-security/2010/09/21/3(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2010/09/27/10(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2010/09/27/4(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2010/09/27/5(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2010/09/27/7(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2010/09/27/8(af854a3a-2127-422b-91ae-364da2661108)
http://openwall.com/lists/oss-security/2010/10/25/2(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/49711(af854a3a-2127-422b-91ae-364da2661108)
http://security.gentoo.org/glsa/glsa-201206-31.xml(af854a3a-2127-422b-91ae-364da2661108)
http://www.openwall.com/lists/oss-security/2010/09/24/2(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2010-0819.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2010-0891.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2011/0606(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=641335(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.