CVE-2010-4706

NONE EPSS 28.7%
Published Jan 24, 201115y ago · Modified Jun 16, 20262w ago
Find Similar
Published Jan 24, 2011 15y ago
Last Modified Jun 16, 2026 2w ago

Description

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

Threat Intelligence

EPSS Exploit Probability
28.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 24

VendorProductVersionRange
linux-pamlinux-pam* ≤1.1.2
linux-pamlinux-pam0.99.1.0any
linux-pamlinux-pam0.99.2.0any
linux-pamlinux-pam0.99.2.1any
linux-pamlinux-pam0.99.3.0any
linux-pamlinux-pam0.99.4.0any
linux-pamlinux-pam0.99.5.0any
linux-pamlinux-pam0.99.6.0any
linux-pamlinux-pam0.99.6.1any
linux-pamlinux-pam0.99.6.2any
linux-pamlinux-pam0.99.6.3any
linux-pamlinux-pam0.99.7.0any
linux-pamlinux-pam0.99.7.1any
linux-pamlinux-pam0.99.8.0any
linux-pamlinux-pam0.99.8.1any
linux-pamlinux-pam0.99.9.0any
linux-pamlinux-pam0.99.10.0any
linux-pamlinux-pam1.0.0any
linux-pamlinux-pam1.0.1any
linux-pamlinux-pam1.0.2any
linux-pamlinux-pam1.0.3any
linux-pamlinux-pam1.0.4any
linux-pamlinux-pam1.1.0any
linux-pamlinux-pam1.1.1any

References 6

Remediation

  • openwall.com http://openwall.com/lists/oss-security/2010/10/03/1
    Patch