CVE-2011-3148
published 2012-07-22CVE-2011-3148: Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a…
PriorityP420medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.70%
48.8th percentile
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.3-5 (bookworm) | pam 1.1.3-5 (bookworm) |
| linux-pam | linux-pam | <= 1.1.4 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
(pam_env): Stack-based buffer overflow by parsing user's pam_environment file
vendor_redhat·2011-10-24·CVSS 4.6
CVE-2011-3148 [MEDIUM] CWE-121 (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
(pam_env): Stack-based buffer overflow by parsing user's pam_environment file
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.
Statement: This issue did not affect the versions of pam package as shipped with Red Hat Enterprise Linux 5.
Package: pam (Red Hat Enterprise Linux 4) - Not affected
Package: pam (Red Hat Enterprise Linux 5) - Not affected
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-10-24·CVSS 4.6
CVE-2011-3149 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: PAM could be made to crash or run programs as an administrator.
Kees Cook discovered that the PAM pam_env module incorrectly handled
certain malformed environment files. A local attacker could use this flaw
to cause a denial of service, or possibly gain privileges. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2011-3148)
Kees Cook discovered that the PAM pam_env module incorrectly handled
variable expansion. A local attacker could use this flaw to cause a denial
of service. (CVE-2011-3149)
Stephane Chazelas discovered that the PAM pam_motd module incorrectly
cleaned the environment during execution of the motd scripts. In certain
environments, a local attacker could use this to execute
Debian
CVE-2011-3148: pam - Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pa...
vendor_debian·2011·CVSS 4.6
CVE-2011-3148 [MEDIUM] CVE-2011-3148: pam - Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pa...
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.
Scope: local
bookworm: resolved (fixed in 1.1.3-5)
bullseye: resolved (fixed in 1.1.3-5)
forky: resolved (fixed in 1.1.3-5)
sid: resolved (fixed in 1.1.3-5)
trixie: resolved (fixed in 1.1.3-5)
GHSA
GHSA-gh7c-55pq-pm8c: Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env
ghsa_unreviewed·2022-05-14
CVE-2011-3148 [MEDIUM] CWE-119 GHSA-gh7c-55pq-pm8c: Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.
OSV
CVE-2011-3148: Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env
osv·2012-07-22·CVSS 4.6
CVE-2011-3148 [MEDIUM] CVE-2011-3148: Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env
Stack-based buffer overflow in the _assemble_line function in modules/pam_env/pam_env.c in Linux-PAM (aka pam) before 1.1.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long string of white spaces at the beginning of the ~/.pam_environment file.
Suricata
ET WEB_CLIENT Microsoft Visio 2003 mfc71enu.dll DLL Loading Arbitrary Code Execution Attempt
suricata·2011-07-27
CVE-2010-3148 ET WEB_CLIENT Microsoft Visio 2003 mfc71enu.dll DLL Loading Arbitrary Code Execution Attempt
ET WEB_CLIENT Microsoft Visio 2003 mfc71enu.dll DLL Loading Arbitrary Code Execution Attempt
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET WEB_CLIENT Microsoft Visio 2003 mfc71enu.dll DLL Loading Arbitrary Code Execution Attempt"; flow:established,to_server; http.uri; content:"/mfc71"; nocase; pcre:"/^[a-z]{2,3}\.dll/Ri"; reference:url,tools.cisco.com/security/center/viewAlert.x?alertId=23601; reference:url,www.microsoft.com/technet/security/bulletin/MS11-055.mspx; reference:bid,42681; reference:cve,2010-3148; classtype:attempted-user; sid:2013322; rev:3; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2011_07_27, cve CVE_2010_3148, deployment Perimeter, confidence Medium, signature_severity Major, tag
No public exploits indexed.
Bugzilla
CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file [fedora-all]
bugzilla·2011-12-14·CVSS 4.6
CVE-2011-3148 [MEDIUM] CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file [fedora-all]
CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraprojec
Bugzilla
CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
bugzilla·2011-10-17·CVSS 4.6
CVE-2011-3148 [MEDIUM] CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
A stack-based buffer overflow flaw was found in the way the pam_env module of PAM (Pluggable Authentication Modules) security tool parsed content of user's ~/.pam_environment file for additional environment variables (the leading whitespace was not count into the count of bytes, which have been read into the buffer), when both pam_env module and reading of the user specific environment file were enabled. A local attacker could use this flaw to crash the pam_env module, or, potentially escalate their privileges.
Discussion:
Acknowledgements:
Red Hat would like to thank Kees Cook of Google ChromeOS Team for reporting this issue.
---
pam_env shipped in Red Hat Enterprise Linux 4 and Red Hat E
http://git.fedorahosted.org/git/?p=linux-pam.git%3Ba=commitdiff%3Bh=caf5e7f61c8d9288daa49b4f61962e6b1239121dhttp://secunia.com/advisories/46583http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.ubuntu.com/usn/USN-1237-1https://bugs.launchpad.net/ubuntu/+source/pam/+bug/874469http://git.fedorahosted.org/git/?p=linux-pam.git%3Ba=commitdiff%3Bh=caf5e7f61c8d9288daa49b4f61962e6b1239121dhttp://secunia.com/advisories/46583http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.ubuntu.com/usn/USN-1237-1https://bugs.launchpad.net/ubuntu/+source/pam/+bug/874469
2012-07-22
Published