CVE-2010-3435
published 2011-01-24CVE-2010-3435: The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to…
PriorityP417medium4.7CVSS 2.0
AVLACMAuNCCINAN
EPSS
0.36%
28.0th percentile
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.3-1 (bookworm) | pam 1.1.3-1 (bookworm) |
| linux-pam | linux-pam | <= 1.1.1 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv4.7MEDIUM
vendor_ubuntu6.6MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM regression
vendor_ubuntu·2011-05-31·CVSS 6.6
[MEDIUM] PAM regression
Title: PAM regression
Summary: The USN-1140-1 PAM update caused cron to stop working.
USN-1140-1 fixed vulnerabilities in PAM. A regression was found that caused
cron to stop working with a "Module is unknown" error. As a result, systems
configured with automatic updates will not receive updates until cron is
restarted, these updates are installed or the system is rebooted. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 6.6
CVE-2009-0887 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: An attacker could cause PAM to read or delete arbitrary files or cause it
to crash.
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM pam_xauth, pam_env and pam_mail modules
incorrectly handled dropping privileges when performing operations. A local
attacker could use this flaw to read certain arbitrary files, and access
other sensitive information. (CVE-2010-3316, CVE-2010-3430, CVE-2010-3431,
CVE-2010-3435)
It was discovered that the PAM pam_namespace module incorrectly cleaned th
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Red Hat
pam: pam_mail and pam_env incorrect privilege dropping
vendor_redhat·2010-09-21·CVSS 4.7
CVE-2010-3430 [MEDIUM] pam: pam_mail and pam_env incorrect privilege dropping
pam: pam_mail and pam_env incorrect privilege dropping
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Statement: Not vulnerable. This issue did not affect the versions of pam as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6.
Package: pam (Red Hat Enterprise Linux 4) - Not affected
Package: pam (Red Hat Enterprise Linux 5) - Not affected
Package: pam (Red Hat Enterprise Linux 6
Red Hat
pam: pam_mail and pam_env incorrect privilege dropping
vendor_redhat·2010-09-21·CVSS 1.9
CVE-2010-3431 [LOW] pam: pam_mail and pam_env incorrect privilege dropping
pam: pam_mail and pam_env incorrect privilege dropping
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Statement: Not vulnerable. This issue did not affect the versions of pam as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6.
Package: pam (Red Hat Enterprise Linux 4) - Not affected
Package: pam (Red Hat Enterprise Linux 5) - Not affected
Package: pam (Red Hat Enterprise Linux 6) - Not affected
Red Hat
pam: pam_env and pam_mail accessing users' file with root privileges
vendor_redhat·2010-09-21·CVSS 4.7
CVE-2010-3435 [MEDIUM] pam: pam_env and pam_mail accessing users' file with root privileges
pam: pam_env and pam_mail accessing users' file with root privileges
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
Package: pam (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2010-3435: pam - The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use...
vendor_debian·2010·CVSS 4.7
CVE-2010-3435 [MEDIUM] CVE-2010-3435: pam - The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use...
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fixed in 1.1.3-1)
sid: resolved (fixed in 1.1.3-1)
trixie: resolved (fixed in 1.1.3-1)
Debian
CVE-2010-3430: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
vendor_debian·2010·CVSS 4.7
CVE-2010-3430 [MEDIUM] CVE-2010-3430: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fixed in 1.1.3-1)
sid: resolved (fixed in 1.1.3-1)
trixie: resolved (fixed in 1.1.3-1)
Debian
CVE-2010-3431: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
vendor_debian·2010·CVSS 1.9
CVE-2010-3431 [LOW] CVE-2010-3431: pam - The privilege-dropping implementation in the (1) pam_env and (2) pam_mail module...
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fixed in 1.1.3-1)
sid: resolved (fixed in 1.1.3-1)
trixie: resolved (fixed in 1.1.3-1)
GHSA
GHSA-65hr-mfq3-4rjr: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
ghsa_unreviewed·2022-05-14·CVSS 4.7
CVE-2010-3431 [MEDIUM] GHSA-65hr-mfq3-4rjr: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
GHSA
GHSA-fw5v-fh36-5x5q: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
ghsa_unreviewed·2022-05-14·CVSS 4.7
CVE-2010-3430 [MEDIUM] GHSA-fw5v-fh36-5x5q: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
GHSA
GHSA-h8pg-g57w-hfr9: The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1
ghsa_unreviewed·2022-05-14
CVE-2010-3435 [MEDIUM] GHSA-h8pg-g57w-hfr9: The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
OSV
CVE-2010-3431: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
osv·2011-01-24·CVSS 1.9
CVE-2010-3431 [LOW] CVE-2010-3431: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
OSV
CVE-2010-3435: The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1
osv·2011-01-24·CVSS 4.7
CVE-2010-3435 [MEDIUM] CVE-2010-3435: The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
OSV
CVE-2010-3430: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
osv·2011-01-24·CVSS 4.7
CVE-2010-3430 [MEDIUM] CVE-2010-3430: The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.
No detection rules found.
Bugzilla
CVE-2010-4708 pam: pam_env: reading ~/.pam_environment is security risk
bugzilla·2011-01-25·CVSS 7.2
CVE-2010-4708 [HIGH] CVE-2010-4708 pam: pam_env: reading ~/.pam_environment is security risk
CVE-2010-4708 pam: pam_env: reading ~/.pam_environment is security risk
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4708 to
the following vulnerability:
The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the
.pam_environment file in a user's home directory, which might allow
local users to run programs with an unintended environment by
executing a program that relies on the pam_env PAM check.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4708
[2] http://openwall.com/lists/oss-security/2010/09/27/7
[3] https://bugzilla.redhat.com/show_bug.cgi?id=641335
[4] http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_env/pam_env.8.xml?r1=1.7&r2=1.8
[5] http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_env/pa
Bugzilla
CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping
bugzilla·2010-10-08·CVSS 4.7
CVE-2010-3430 [MEDIUM] CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping
CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping
The pam_mail and pam_env modules in Linux-PAM before 1.1.2 did not drop privileges before accessing users' files (CVE-2010-3435, see bug #641335). Privilege dropping was added in 1.1.2, but with couple of issues pointed out by Solar Designer:
http://thread.gmane.org/gmane.comp.security.oss.general/3311/focus=3534
The code fails to switch fsgid/egid and groups (CVE-2010-3430) and does not check setfsuid() return value (CVE-2010-3431). Fix using newly-introduced pam_modutil_drop_priv / pam_modutil_regain_priv was committed in upstream CVS and should be included in 1.1.3:
http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commitdiff;h=843807a3a90f52e7538be756616510730a24739a
Discussion:
Linux-PAM 1.1
Bugzilla
CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges
bugzilla·2010-10-08·CVSS 4.7
CVE-2010-3435 [MEDIUM] CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges
CVE-2010-3435 pam: pam_env and pam_mail accessing users' file with root privileges
It was reported that pam_env and pam_mail modules do not drop privileges before accessing users' files. This flaw can lead to information disclosure.
Issue was partially addressed in Linux-PAM 1.1.2:
http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commitdiff;h=06f882f30092a39a1db867c9744b2ca8d60e4ad6
The fix in 1.1.2 has some problems though, it fails to switch fsgid/egid and groups (CVE-2010-3430) and does not check setfsuid() return value (CVE-2010-3431):
http://thread.gmane.org/gmane.comp.security.oss.general/3311/focus=3551
Fix using newly-introduced pam_modutil_drop_priv / pam_modutil_regain_priv was committed in upstream CVS and should be included in 1.1.3:
http://git.altlinux.org/people/l
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=06f882f30092a39a1db867c9744b2ca8d60e4ad6http://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://openwall.com/lists/oss-security/2010/09/21/3http://openwall.com/lists/oss-security/2010/09/27/10http://openwall.com/lists/oss-security/2010/09/27/4http://openwall.com/lists/oss-security/2010/09/27/5http://openwall.com/lists/oss-security/2010/09/27/7http://openwall.com/lists/oss-security/2010/09/27/8http://openwall.com/lists/oss-security/2010/10/25/2http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:220http://www.openwall.com/lists/oss-security/2010/09/24/2http://www.redhat.com/support/errata/RHSA-2010-0819.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0891.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=641335http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=06f882f30092a39a1db867c9744b2ca8d60e4ad6http://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://openwall.com/lists/oss-security/2010/09/21/3http://openwall.com/lists/oss-security/2010/09/27/10http://openwall.com/lists/oss-security/2010/09/27/4http://openwall.com/lists/oss-security/2010/09/27/5http://openwall.com/lists/oss-security/2010/09/27/7http://openwall.com/lists/oss-security/2010/09/27/8http://openwall.com/lists/oss-security/2010/10/25/2http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:220http://www.openwall.com/lists/oss-security/2010/09/24/2http://www.redhat.com/support/errata/RHSA-2010-0819.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0891.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=641335
2011-01-24
Published