CVE-2010-3431
published 2011-01-24CVE-2010-3431: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid…
PriorityP44low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.35%
27.1th percentile
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.3-1 (bookworm) | pam 1.1.3-1 (bookworm) |
| linux-pam | linux-pam | — | — |
| pam | pam | >= 0 < 1.1.3-1 | 1.1.3-1 |
| pam | pam | >= 0 < 1.1.3-1 | 1.1.3-1 |
| pam | pam | >= 0 < 1.1.3-1 | 1.1.3-1 |
| pam | pam | >= 0 < 1.1.3-1 | 1.1.3-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_ubuntu6.6MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65hr-mfq3-4rjr: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
ghsa_unreviewed·2022-05-14·CVSS 4.7
CVE-2010-3431 [MEDIUM] GHSA-65hr-mfq3-4rjr: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
OSV
CVE-2010-3431: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
osv·2011-01-24·CVSS 1.9
CVE-2010-3431 [LOW] CVE-2010-3431: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Ubuntu
PAM regression
vendor_ubuntu·2011-05-31·CVSS 6.6
[MEDIUM] PAM regression
Title: PAM regression
Summary: The USN-1140-1 PAM update caused cron to stop working.
USN-1140-1 fixed vulnerabilities in PAM. A regression was found that caused
cron to stop working with a "Module is unknown" error. As a result, systems
configured with automatic updates will not receive updates until cron is
restarted, these updates are installed or the system is rebooted. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 6.6
CVE-2009-0887 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: An attacker could cause PAM to read or delete arbitrary files or cause it
to crash.
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM pam_xauth, pam_env and pam_mail modules
incorrectly handled dropping privileges when performing operations. A local
attacker could use this flaw to read certain arbitrary files, and access
other sensitive information. (CVE-2010-3316, CVE-2010-3430, CVE-2010-3431,
CVE-2010-3435)
It was discovered that the PAM pam_namespace module incorrectly cleaned th
Red Hat
pam: pam_mail and pam_env incorrect privilege dropping
vendor_redhat·2010-09-21·CVSS 1.9
CVE-2010-3431 [LOW] pam: pam_mail and pam_env incorrect privilege dropping
pam: pam_mail and pam_env incorrect privilege dropping
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Statement: Not vulnerable. This issue did not affect the versions of pam as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6.
Package: pam (Red Hat Enterprise Linux 4) - Not affected
Package: pam (Red Hat Enterprise Linux 5) - Not affected
Package: pam (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-3431: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
vendor_debian·2010·CVSS 1.9
CVE-2010-3431 [LOW] CVE-2010-3431: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fixed in 1.1.3-1)
sid: resolved (fixed in 1.1.3-1)
trixie: resolved (fixed in 1.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping
bugzilla·2010-10-08·CVSS 4.7
CVE-2010-3430 [MEDIUM] CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping
CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping
The pam_mail and pam_env modules in Linux-PAM before 1.1.2 did not drop privileges before accessing users' files (CVE-2010-3435, see bug #641335). Privilege dropping was added in 1.1.2, but with couple of issues pointed out by Solar Designer:
http://thread.gmane.org/gmane.comp.security.oss.general/3311/focus=3534
The code fails to switch fsgid/egid and groups (CVE-2010-3430) and does not check setfsuid() return value (CVE-2010-3431). Fix using newly-introduced pam_modutil_drop_priv / pam_modutil_regain_priv was committed in upstream CVS and should be included in 1.1.3:
http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commitdiff;h=843807a3a90f52e7538be756616510730a24739a
Discussion:
Linux-PAM 1.1
Bugzilla
CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges
bugzilla·2010-10-08·CVSS 4.7
CVE-2010-3435 [MEDIUM] CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges
CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges
It was reported that pam_env and pam_mail modules do not drop privileges before accessing users' files. This flaw can lead to information disclosure.
Issue was partially addressed in Linux-PAM 1.1.2:
http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commitdiff;h=06f882f30092a39a1db867c9744b2ca8d60e4ad6
The fix in 1.1.2 has some problems though, it fails to switch fsgid/egid and groups (CVE-2010-3430) and does not check setfsuid() return value (CVE-2010-3431):
http://thread.gmane.org/gmane.comp.security.oss.general/3311/focus=3551
Fix using newly-introduced pam_modutil_drop_priv / pam_modutil_regain_priv was committed in upstream CVS and should be included in 1.1.3:
http://git.altlinux.org/people/l
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=843807a3a90f52e7538be756616510730a24739ahttp://openwall.com/lists/oss-security/2010/09/21/10http://openwall.com/lists/oss-security/2010/09/21/3http://openwall.com/lists/oss-security/2010/09/21/8http://openwall.com/lists/oss-security/2010/09/21/9http://openwall.com/lists/oss-security/2010/09/27/10http://openwall.com/lists/oss-security/2010/09/27/4http://openwall.com/lists/oss-security/2010/09/27/5http://openwall.com/lists/oss-security/2010/09/27/7http://openwall.com/lists/oss-security/2010/10/03/1http://openwall.com/lists/oss-security/2010/10/25/2http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.openwall.com/lists/oss-security/2010/09/21/11http://www.openwall.com/lists/oss-security/2010/09/24/2https://bugzilla.redhat.com/show_bug.cgi?id=641361http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=843807a3a90f52e7538be756616510730a24739ahttp://openwall.com/lists/oss-security/2010/09/21/10http://openwall.com/lists/oss-security/2010/09/21/3http://openwall.com/lists/oss-security/2010/09/21/8http://openwall.com/lists/oss-security/2010/09/21/9http://openwall.com/lists/oss-security/2010/09/27/10http://openwall.com/lists/oss-security/2010/09/27/4http://openwall.com/lists/oss-security/2010/09/27/5http://openwall.com/lists/oss-security/2010/09/27/7http://openwall.com/lists/oss-security/2010/10/03/1http://openwall.com/lists/oss-security/2010/10/25/2http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.openwall.com/lists/oss-security/2010/09/21/11http://www.openwall.com/lists/oss-security/2010/09/24/2https://bugzilla.redhat.com/show_bug.cgi?id=641361
2011-01-24
Published