CVE-2010-4706
published 2011-01-24CVE-2010-4706: The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.37%
29.0th percentile
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.3-1 (bookworm) | pam 1.1.3-1 (bookworm) |
| linux-pam | linux-pam | <= 1.1.2 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu6.6MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PAM regression
vendor_ubuntu·2011-05-31·CVSS 6.6
[MEDIUM] PAM regression
Title: PAM regression
Summary: The USN-1140-1 PAM update caused cron to stop working.
USN-1140-1 fixed vulnerabilities in PAM. A regression was found that caused
cron to stop working with a "Module is unknown" error. As a result, systems
configured with automatic updates will not receive updates until cron is
restarted, these updates are installed or the system is rebooted. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-05-30·CVSS 6.6
CVE-2009-0887 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: An attacker could cause PAM to read or delete arbitrary files or cause it
to crash.
Marcus Granado discovered that PAM incorrectly handled configuration files
with non-ASCII usernames. A remote attacker could use this flaw to cause a
denial of service, or possibly obtain login access with a different users
username. This issue only affected Ubuntu 8.04 LTS. (CVE-2009-0887)
It was discovered that the PAM pam_xauth, pam_env and pam_mail modules
incorrectly handled dropping privileges when performing operations. A local
attacker could use this flaw to read certain arbitrary files, and access
other sensitive information. (CVE-2010-3316, CVE-2010-3430, CVE-2010-3431,
CVE-2010-3435)
It was discovered that the PAM pam_namespace module incorrectly cleaned th
Red Hat
pam: pam_xauth: Improper handling of failure to determine certain target uid
vendor_redhat·2010-10-03·CVSS 4.9
CVE-2010-4706 [MEDIUM] pam: pam_xauth: Improper handling of failure to determine certain target uid
pam: pam_xauth: Improper handling of failure to determine certain target uid
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
Statement: Red Hat does not consider this issue to be a security flaw. For additional details, refer to: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4706
Package: pam (Red Hat Enterprise Linux 4) - Affected
Package: pam (Red Hat Enterprise Linux 5) - Not affected
Package: pam (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-4706: pam - The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linu...
vendor_debian·2010·CVSS 4.9
CVE-2010-4706 [MEDIUM] CVE-2010-4706: pam - The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linu...
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
Scope: local
bookworm: resolved (fixed in 1.1.3-1)
bullseye: resolved (fixed in 1.1.3-1)
forky: resolved (fixed in 1.1.3-1)
sid: resolved (fixed in 1.1.3-1)
trixie: resolved (fixed in 1.1.3-1)
GHSA
GHSA-34fx-r4jh-7jxc: The pam_sm_close_session function in pam_xauth
ghsa_unreviewed·2022-05-14
CVE-2010-4706 [MEDIUM] GHSA-34fx-r4jh-7jxc: The pam_sm_close_session function in pam_xauth
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
OSV
CVE-2010-4706: The pam_sm_close_session function in pam_xauth
osv·2011-01-24·CVSS 4.9
CVE-2010-4706 [MEDIUM] CVE-2010-4706: The pam_sm_close_session function in pam_xauth
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
No detection rules found.
No public exploits indexed.
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=Linux-PAM-1_1_2-3-g05dafc06cd3dfeb7c4b24942e4e1ae33ff75a123http://openwall.com/lists/oss-security/2010/10/03/1http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.securityfocus.com/bid/46045https://exchange.xforce.ibmcloud.com/vulnerabilities/65035http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=Linux-PAM-1_1_2-3-g05dafc06cd3dfeb7c4b24942e4e1ae33ff75a123http://openwall.com/lists/oss-security/2010/10/03/1http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.securityfocus.com/bid/46045https://exchange.xforce.ibmcloud.com/vulnerabilities/65035
2011-01-24
Published