CVE-2011-3628
published 2014-04-15CVE-2011-3628: Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.38%
30.7th percentile
Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session optional pam_motd.so", allows local users to gain privileges by modifying the PATH environment variable to reference a malicious command, as demonstrated via uname.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | libpam-modules | — | — |
| canonical | libpam-modules | — | — |
| canonical | libpam-modules | — | — |
| canonical | libpam-modules | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | pam | < pam 1.1.3-7 (bookworm) | pam 1.1.3-7 (bookworm) |
| pam | pam | >= 0 < 1.1.3-7 | 1.1.3-7 |
| pam | pam | >= 0 < 1.1.3-7 | 1.1.3-7 |
| pam | pam | >= 0 < 1.1.3-7 | 1.1.3-7 |
| pam | pam | >= 0 < 1.1.3-7 | 1.1.3-7 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9LOW
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9hgw-rg97-xh38: Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1
ghsa_unreviewed·2022-05-17
CVE-2011-3628 [MEDIUM] GHSA-9hgw-rg97-xh38: Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1
Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session optional pam_motd.so", allows local users to gain privileges by modifying the PATH environment variable to reference a malicious command, as demonstrated via uname.
OSV
CVE-2011-3628: Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1
osv·2014-04-15·CVSS 6.9
CVE-2011-3628 [MEDIUM] CVE-2011-3628: Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1
Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session optional pam_motd.so", allows local users to gain privileges by modifying the PATH environment variable to reference a malicious command, as demonstrated via uname.
Ubuntu
PAM vulnerabilities
vendor_ubuntu·2011-10-24·CVSS 4.6
CVE-2011-3149 [MEDIUM] PAM vulnerabilities
Title: PAM vulnerabilities
Summary: PAM could be made to crash or run programs as an administrator.
Kees Cook discovered that the PAM pam_env module incorrectly handled
certain malformed environment files. A local attacker could use this flaw
to cause a denial of service, or possibly gain privileges. The default
compiler options for affected releases should reduce the vulnerability to a
denial of service. (CVE-2011-3148)
Kees Cook discovered that the PAM pam_env module incorrectly handled
variable expansion. A local attacker could use this flaw to cause a denial
of service. (CVE-2011-3149)
Stephane Chazelas discovered that the PAM pam_motd module incorrectly
cleaned the environment during execution of the motd scripts. In certain
environments, a local attacker could use this to execute
Debian
CVE-2011-3628: pam - Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-...
vendor_debian·2011·CVSS 6.9
CVE-2011-3628 [MEDIUM] CVE-2011-3628: pam - Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-...
Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session optional pam_motd.so", allows local users to gain privileges by modifying the PATH environment variable to reference a malicious command, as demonstrated via uname.
Scope: local
bookworm: resolved (fixed in 1.1.3-7)
bullseye: resolved (fixed in 1.1.3-7)
forky: resolved (fixed in 1.1.3-7)
sid: resolved (fixed in 1.1.3-7)
trixie: resolved (fixed in 1.1.3-7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-15
Published