CVE-2010-3316
published 2011-01-24CVE-2010-3316: The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid…
PriorityP411low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.37%
28.9th percentile
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.2-1 (bookworm) | pam 1.1.2-1 (bookworm) |
| linux-pam | linux-pam | <= 1.1.1 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| pam | pam | >= 0 < 1.1.2-1 | 1.1.2-1 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv3.3LOW
vendor_ubuntu6.6MEDIUM
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xj4j-67v3-3wr4: The run_coprocess function in pam_xauth
ghsa_unreviewed·2022-05-14
CVE-2010-3316 [LOW] GHSA-xj4j-67v3-3wr4: The run_coprocess function in pam_xauth
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
OSV
CVE-2010-3316: The run_coprocess function in pam_xauth
osv·2011-01-24·CVSS 3.3
CVE-2010-3316 [LOW] CVE-2010-3316: The run_coprocess function in pam_xauth
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
Ubuntu
PAM regression
vendor_ubuntu·2011-05-31·CVSS 6.6
[MEDIUM] PAM regression
Title: PAM regression
Summary: The USN-1140-1 PAM update caused cron to stop working.
USN-1140-1 fixed vulnerabilities in PAM. A regression was found that caused
cron to stop working with a "Module is unknown" error. As a result, systems
configured with automatic updates will not receive updates until cron is
restarted, these updates are installed or the system is rebooted. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 6.6
CVE-2009-0887 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: An attacker could cause PAM to read or delete arbitrary files or cause it
to crash.
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM pam_xauth, pam_env and pam_mail modules
incorrectly handled dropping privileges when performing operations. A local
attacker could use this flaw to read certain arbitrary files, and access
other sensitive information. (CVE-2010-3316, CVE-2010-3430, CVE-2010-3431,
CVE-2010-3435)
It was discovered that the PAM pam_namespace module incorrectly cleaned th
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Red Hat
pam: pam_xauth missing return value checks from setuid() and similar calls
vendor_redhat·2010-07-20·CVSS 3.3
CVE-2010-3316 [LOW] pam: pam_xauth missing return value checks from setuid() and similar calls
pam: pam_xauth missing return value checks from setuid() and similar calls
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
Package: pam (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2010-3316: pam - The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (...
vendor_debian·2010·CVSS 3.3
CVE-2010-3316 [LOW] CVE-2010-3316: pam - The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (...
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
Scope: local
bookworm: resolved (fixed in 1.1.2-1)
bullseye: resolved (fixed in 1.1.2-1)
forky: resolved (fixed in 1.1.2-1)
sid: resolved (fixed in 1.1.2-1)
trixie: resolved (fixed in 1.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4706 pam: pam_xauth: Improper handling of failure to determine certain target uid
bugzilla·2011-01-25·CVSS 4.9
CVE-2010-4706 [MEDIUM] CVE-2010-4706 pam: pam_xauth: Improper handling of failure to determine certain target uid
CVE-2010-4706 pam: pam_xauth: Improper handling of failure to determine certain target uid
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4706 to
the following vulnerability:
The pam_sm_close_session function in pam_xauth.c in the pam_xauth
module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly
handle a failure to determine a certain target uid, which might allow
local users to delete unintended files by executing a program that
relies on the pam_xauth PAM check.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4706
[2] http://openwall.com/lists/oss-security/2010/10/03/1
[3] http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=Linux-PAM-1_1_2-3-g05dafc06cd3dfeb7c4b24942e4e1ae33ff75a123
Discussion:
This issue affects t
Bugzilla
CVE-2010-3316 pam: pam_xauth missing return value checks from setuid() and similar calls
bugzilla·2010-09-27·CVSS 3.3
CVE-2010-3316 [LOW] CVE-2010-3316 pam: pam_xauth missing return value checks from setuid() and similar calls
CVE-2010-3316 pam: pam_xauth missing return value checks from setuid() and similar calls
Tim Brown reported [1] a minor security flaw in pam_xauth where the run_coprocess() function, which is responsible for running 'xauth nlist' as the existing user and 'xauth merge' as the target user does not check the return code on the setuid() call. An attacker with the ability to manipulate the number of processes running on the target account can cause RLIMIT_NPROC to be breached when run_coprocess() is called to execute 'xauth merge' as the target user.
This issue was assigned the name CVE-2010-3316 [2] and is corrected in Linux-PAM 1.1.2 [3].
It is not believed to be exploitable on current kernels, at least not via RLIMIT_NPROC [4].
[1] https://sourceforge.net/tracker/?func=detail&aid=3028213
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=06f882f30092a39a1db867c9744b2ca8d60e4ad6http://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://openwall.com/lists/oss-security/2010/08/16/2http://openwall.com/lists/oss-security/2010/09/21/3http://openwall.com/lists/oss-security/2010/09/21/8http://openwall.com/lists/oss-security/2010/09/27/10http://openwall.com/lists/oss-security/2010/09/27/4http://openwall.com/lists/oss-security/2010/09/27/5http://openwall.com/lists/oss-security/2010/09/27/7http://openwall.com/lists/oss-security/2010/10/25/2http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:220http://www.openwall.com/lists/oss-security/2010/09/24/2http://www.redhat.com/support/errata/RHSA-2010-0819.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0891.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=637898https://sourceforge.net/tracker/?func=detail&aid=3028213&group_id=6663&atid=106663http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=06f882f30092a39a1db867c9744b2ca8d60e4ad6http://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://openwall.com/lists/oss-security/2010/08/16/2http://openwall.com/lists/oss-security/2010/09/21/3http://openwall.com/lists/oss-security/2010/09/21/8http://openwall.com/lists/oss-security/2010/09/27/10http://openwall.com/lists/oss-security/2010/09/27/4http://openwall.com/lists/oss-security/2010/09/27/5http://openwall.com/lists/oss-security/2010/09/27/7http://openwall.com/lists/oss-security/2010/10/25/2http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:220http://www.openwall.com/lists/oss-security/2010/09/24/2http://www.redhat.com/support/errata/RHSA-2010-0819.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0891.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=637898https://sourceforge.net/tracker/?func=detail&aid=3028213&group_id=6663&atid=106663
2011-01-24
Published