cbcvebase.
CVE-2010-3316
published 2011-01-24

CVE-2010-3316: The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid…

PriorityP411low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.37%
28.9th percentile
The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianpam< pam 1.1.2-1 (bookworm)pam 1.1.2-1 (bookworm)
linux-pamlinux-pam<= 1.1.1
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
pampam>= 0 < 1.1.2-11.1.2-1

CVSS provenance

nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv3.3LOW
vendor_ubuntu6.6MEDIUM
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.