cbcvebase.
CVE-2010-4707
published 2011-01-24

CVE-2010-4707: The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular…

PriorityP412medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.36%
28.2th percentile
The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianpam< pam 1.1.3-1 (bookworm)pam 1.1.3-1 (bookworm)
linux-pamlinux-pam<= 1.1.2
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam
linux-pamlinux-pam

CVSS provenance

nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv4.9MEDIUM
vendor_ubuntu6.6MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.