Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-3435
Description:The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
Test IDs: 1.3.6.1.4.1.25623.1.0.68398   1.3.6.1.4.1.25623.1.0.68604   1.3.6.1.4.1.25623.1.0.68384   1.3.6.1.4.1.25623.1.0.68290   1.3.6.1.4.1.25623.1.0.69190   1.3.6.1.4.1.25623.1.0.122300   1.3.6.1.4.1.25623.1.0.122256  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-3435
20110308 VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
http://www.securityfocus.com/archive/1/516909/100/0/threaded
49711
http://secunia.com/advisories/49711
ADV-2011-0606
http://www.vupen.com/english/advisories/2011/0606
GLSA-201206-31
http://security.gentoo.org/glsa/glsa-201206-31.xml
MDVSA-2010:220
http://www.mandriva.com/security/advisories?name=MDVSA-2010:220
RHSA-2010:0819
http://www.redhat.com/support/errata/RHSA-2010-0819.html
RHSA-2010:0891
http://www.redhat.com/support/errata/RHSA-2010-0891.html
[oss-security] 20100921 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/09/21/3
[oss-security] 20100924 Re: Minor security flaw with pam_xauth
http://www.openwall.com/lists/oss-security/2010/09/24/2
[oss-security] 20100927 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/09/27/4
[oss-security] 20100927 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/09/27/5
[oss-security] 20100927 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/09/27/8
[oss-security] 20100928 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/09/27/10
[oss-security] 20100928 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/09/27/7
[oss-security] 20101025 Re: Minor security flaw with pam_xauth
http://openwall.com/lists/oss-security/2010/10/25/2
[security-announce] 20110307 VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm
http://lists.vmware.com/pipermail/security-announce/2011/000126.html
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=06f882f30092a39a1db867c9744b2ca8d60e4ad6
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=06f882f30092a39a1db867c9744b2ca8d60e4ad6
http://www.vmware.com/security/advisories/VMSA-2011-0004.html
http://www.vmware.com/security/advisories/VMSA-2011-0004.html
https://bugzilla.redhat.com/show_bug.cgi?id=641335
https://bugzilla.redhat.com/show_bug.cgi?id=641335




© 1998-2025 E-Soft Inc. All rights reserved.