CVE-2010-4707Linux-pam vulnerability

CWE-3998 documents7 sources
Severity
4.9MEDIUMNVD
EPSS
0.1%
top 73.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 24
Latest updateMay 14

Description

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

CVSS vector

AV:L/AC:L/C:C/I:N/A:NExploitability: 3.9 | Impact: 6.9

Affected Packages3 packages

NVDlinux-pam/linux-pam1.1.2+23
debiandebian/pam< pam 1.1.3-1 (bookworm)
Debianpam/pam< 1.1.3-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-frff-99c9-q6rc: The check_acl function in pam_xauth2022-05-14
OSV
CVE-2010-4707: The check_acl function in pam_xauth2011-01-24

📋Vendor Advisories

4
Ubuntu
PAM regression2011-05-31
Ubuntu
PAM vulnerabilities2011-05-30
Red Hat
pam: pam_xauth: Does not check if certain ACL file is a regular file2010-10-03
Debian
CVE-2010-4707: pam - The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka ...2010

💬Community

1
Bugzilla
CVE-2010-4707 pam: pam_xauth: Does not check if certain ACL file is a regular file2011-01-25
CVE-2010-4707 — Linux-pam vulnerability | cvebase