CVE-2011-3149
published 2012-07-22CVE-2011-3149: The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.53%
41.4th percentile
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pam | < pam 1.1.3-5 (bookworm) | pam 1.1.3-5 (bookworm) |
| linux-pam | linux-pam | <= 1.1.4 | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
| linux-pam | linux-pam | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_ubuntu4.6MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
(pam_env): Infinite loop by expanding certain arguments
vendor_redhat·2011-10-24·CVSS 2.1
CVE-2011-3149 [LOW] CWE-835 (pam_env): Infinite loop by expanding certain arguments
(pam_env): Infinite loop by expanding certain arguments
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).
Statement: This issue did not affect the versions of pam package as shipped with Red Hat Enterprise Linux 4 and 5.
Package: pam (Red Hat Enterprise Linux 4) - Not affected
Package: pam (Red Hat Enterprise Linux 5) - Not affected
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-10-24·CVSS 4.6
CVE-2011-3149 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: PAM could be made to crash or run programs as an administrator.
Kees Cook discovered that the PAM pam_env module incorrectly handled
certain malformed environment files. A local attacker could use this flaw
to cause a denial of service, or possibly gain privileges. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2011-3148)
Kees Cook discovered that the PAM pam_env module incorrectly handled
variable expansion. A local attacker could use this flaw to cause a denial
of service. (CVE-2011-3149)
Stephane Chazelas discovered that the PAM pam_motd module incorrectly
cleaned the environment during execution of the motd scripts. In certain
environments, a local attacker could use this to execute
Debian
CVE-2011-3149: pam - The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Li...
vendor_debian·2011·CVSS 2.1
CVE-2011-3149 [LOW] CVE-2011-3149: pam - The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Li...
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).
Scope: local
bookworm: resolved (fixed in 1.1.3-5)
bullseye: resolved (fixed in 1.1.3-5)
forky: resolved (fixed in 1.1.3-5)
sid: resolved (fixed in 1.1.3-5)
trixie: resolved (fixed in 1.1.3-5)
GHSA
GHSA-5wc7-486v-w943: The _expand_arg function in the pam_env module (modules/pam_env/pam_env
ghsa_unreviewed·2022-05-14
CVE-2011-3149 [LOW] CWE-119 GHSA-5wc7-486v-w943: The _expand_arg function in the pam_env module (modules/pam_env/pam_env
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).
OSV
CVE-2011-3149: The _expand_arg function in the pam_env module (modules/pam_env/pam_env
osv·2012-07-22·CVSS 2.1
CVE-2011-3149 [LOW] CVE-2011-3149: The _expand_arg function in the pam_env module (modules/pam_env/pam_env
The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3149 pam (pam_env): Infinite loop by expanding certain arguments [fedora-all]
bugzilla·2011-10-25·CVSS 2.1
CVE-2011-3149 [LOW] CVE-2011-3149 pam (pam_env): Infinite loop by expanding certain arguments [fedora-all]
CVE-2011-3149 pam (pam_env): Infinite loop by expanding certain arguments [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=746620
Please note: this issue affe
Bugzilla
CVE-2011-3149 pam (pam_env): Infinite loop by expanding certain arguments
bugzilla·2011-10-17·CVSS 2.1
CVE-2011-3149 [LOW] CVE-2011-3149 pam (pam_env): Infinite loop by expanding certain arguments
CVE-2011-3149 pam (pam_env): Infinite loop by expanding certain arguments
An infinite loop flaw was found in the way the pam_env module of PAM (Pluggable Authentication Modules) security tool expanded certain environment variables, when both pam_env module and reading of the user specific environment file were enabled. A local attacker could use this flaw to cause the pam_env module check to enter the infinite loop and spam system log file of the particular host.
Discussion:
Acknowledgements:
Red Hat would like to thank Kees Cook of Google ChromeOS Team for reporting
this issue.
---
Reading of user-supplied environment files is disabled by default in the pam package versions, as shipped with various releases of Red Hat Enterprise Linux and Fedora, more information at:
https://bugzil
Bugzilla
CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
bugzilla·2011-10-17·CVSS 4.6
CVE-2011-3148 [MEDIUM] CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
CVE-2011-3148 pam (pam_env): Stack-based buffer overflow by parsing user's pam_environment file
A stack-based buffer overflow flaw was found in the way the pam_env module of PAM (Pluggable Authentication Modules) security tool parsed content of user's ~/.pam_environment file for additional environment variables (the leading whitespace was not count into the count of bytes, which have been read into the buffer), when both pam_env module and reading of the user specific environment file were enabled. A local attacker could use this flaw to crash the pam_env module, or, potentially escalate their privileges.
Discussion:
Acknowledgements:
Red Hat would like to thank Kees Cook of Google ChromeOS Team for reporting this issue.
---
pam_env shipped in Red Hat Enterprise Linux 4 and Red Hat E
http://git.fedorahosted.org/git/?p=linux-pam.git%3Ba=commitdiff%3Bh=109823cb621c900c07c4b6cdc99070d354d19444http://secunia.com/advisories/46583http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.ubuntu.com/usn/USN-1237-1https://bugs.launchpad.net/ubuntu/+source/pam/+bug/874565http://git.fedorahosted.org/git/?p=linux-pam.git%3Ba=commitdiff%3Bh=109823cb621c900c07c4b6cdc99070d354d19444http://secunia.com/advisories/46583http://secunia.com/advisories/49711http://security.gentoo.org/glsa/glsa-201206-31.xmlhttp://www.ubuntu.com/usn/USN-1237-1https://bugs.launchpad.net/ubuntu/+source/pam/+bug/874565
2012-07-22
Published