CVE-2013-1052
published 2013-03-21CVE-2013-1052: pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.45%
37.1th percentile
pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4qvx-5chg-whr8: pam-xdg-support, as used in Ubuntu 12
ghsa_unreviewed·2022-05-17
CVE-2013-1052 [HIGH] GHSA-4qvx-5chg-whr8: pam-xdg-support, as used in Ubuntu 12
pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.
Ubuntu
pam-xdg-support vulnerability
vendor_ubuntu·2013-03-18
CVE-2013-1052 pam-xdg-support vulnerability
Title: pam-xdg-support vulnerability
Summary: pam-xdg-support could be made to run programs as an administrator.
Zbigniew Tenerowicz and Sebastian Krzyszkowiak discovered that
pam-xdg-support incorrectly handled the PATH environment variable. A local
attacker could use this issue in combination with sudo to possibly escalate
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-03-21
Published