CVE-2010-3853
published 2011-01-24CVE-2010-3853: pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of…
PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.42%
33.8th percentile
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.3-1 (bookworm) | pam 1.1.3-1 (bookworm) |
| linux-pam | linux-pam | <= 1.1.2 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_redhat6.9MEDIUM
vendor_ubuntu6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM regression
vendor_ubuntu·2011-05-31·CVSS 6.6
[MEDIUM] PAM regression
Title: PAM regression
Summary: The USN-1140-1 PAM update caused cron to stop working.
USN-1140-1 fixed vulnerabilities in PAM. A regression was found that caused
cron to stop working with a "Module is unknown" error. As a result, systems
configured with automatic updates will not receive updates until cron is
restarted, these updates are installed or the system is rebooted. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 6.6
CVE-2009-0887 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: An attacker could cause PAM to read or delete arbitrary files or cause it
to crash.
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM pam_xauth, pam_env and pam_mail modules
incorrectly handled dropping privileges when performing operations. A local
attacker could use this flaw to read certain arbitrary files, and access
other sensitive information. (CVE-2010-3316, CVE-2010-3430, CVE-2010-3431,
CVE-2010-3435)
It was discovered that the PAM pam_namespace module incorrectly cleaned th
VMware
VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
vendor_vmware·2011-03-07·CVSS 5.0
CVE-2010-2059 [MEDIUM] VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
VMSA-2011-0004: VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
a. Service Location Protocol daemon DoS This patch fixes a denial-of-service vulnerability in the Service Location Protocol daemon (SLPD). Exploitation of this vulnerability could cause SLPD to consume significant CPU resources. VMware would like to thank Nicolas Gregoire and US CERT for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2010-3609 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product ============= Product Version ======= Running on ======= Replace with/
Red Hat
pam: pam_namespace executes namespace.init with service's environment
vendor_redhat·2010-10-22·CVSS 6.9
CVE-2010-3853 [MEDIUM] pam: pam_namespace executes namespace.init with service's environment
pam: pam_namespace executes namespace.init with service's environment
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
Package: pam (Red Hat Enterprise Linux 4) - Not affected
Debian
CVE-2010-3853: pam - pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 ...
vendor_debian·2010·CVSS 6.9
CVE-2010-3853 [MEDIUM] CVE-2010-3853: pam - pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 ...
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fixed in 1.1.3-1)
sid: resolved (fixed in 1.1.3-1)
trixie: resolved (fixed in 1.1.3-1)
GHSA
GHSA-94f7-h6jj-cq78: pam_namespace
ghsa_unreviewed·2022-05-14
CVE-2010-3853 [MEDIUM] GHSA-94f7-h6jj-cq78: pam_namespace
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
OSV
CVE-2010-3853: pam_namespace
osv·2011-01-24·CVSS 6.9
CVE-2010-3853 [MEDIUM] CVE-2010-3853: pam_namespace
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.
No detection rules found.
http://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_namespace/pam_namespace.c?view=log#rev1.13http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:220http://www.redhat.com/support/errata/RHSA-2010-0819.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0891.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=643043http://lists.vmware.com/pipermail/security-announce/2011/000126.htmlhttp://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_namespace/pam_namespace.c?view=log#rev1.13http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:220http://www.redhat.com/support/errata/RHSA-2010-0819.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0891.htmlhttp://www.securityfocus.com/archive/1/516909/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2011-0004.htmlhttp://www.vupen.com/english/advisories/2011/0606https://bugzilla.redhat.com/show_bug.cgi?id=643043
2011-01-24
Published