6.9
CVSSv2

CVE-2010-3853

Published: 24/01/2011 Updated: 03/01/2019
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) prior to 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

Vulnerable Product Search on Vulmon Subscribe to Product

linux-pam linux-pam 1.0.4

linux-pam linux-pam 1.0.2

linux-pam linux-pam 1.1.0

linux-pam linux-pam 0.99.7.1

linux-pam linux-pam 0.99.8.0

linux-pam linux-pam 1.0.3

linux-pam linux-pam 1.1.1

linux-pam linux-pam 0.99.6.3

linux-pam linux-pam 0.99.7.0

linux-pam linux-pam 0.99.4.0

linux-pam linux-pam

linux-pam linux-pam 0.99.9.0

linux-pam linux-pam 0.99.8.1

linux-pam linux-pam 0.99.6.1

linux-pam linux-pam 0.99.6.2

linux-pam linux-pam 0.99.2.1

linux-pam linux-pam 0.99.3.0

linux-pam linux-pam 1.0.1

linux-pam linux-pam 1.0.0

linux-pam linux-pam 0.99.5.0

linux-pam linux-pam 0.99.6.0

linux-pam linux-pam 0.99.10.0

linux-pam linux-pam 0.99.1.0

linux-pam linux-pam 0.99.2.0

Vendor Advisories

Debian Bug report logs - #599832 CVE-2010-3316 CVE-2010-3430 CVE-2010-3431 CVE-2010-3435 Package: pam; Maintainer for pam is Steve Langasek <vorlon@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 11 Oct 2010 17:54:05 UTC Severity: important Tags: security Fixed in version pam/113-1 Done: ...
Debian Bug report logs - #608273 CVE-2010-3853: pam_namespace executes namespaceinit with service's environment Package: pam; Maintainer for pam is Steve Langasek <vorlon@debianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Wed, 29 Dec 2010 15:18:02 UTC Severity: serious Tags: patch, security Fix ...
An attacker could cause PAM to read or delete arbitrary files or cause it to crash ...
The USN-1140-1 PAM update caused cron to stop working ...