7.2
CVSSv2

CVE-2010-4708

Published: 24/01/2011 Updated: 03/01/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The pam_env module in Linux-PAM (aka pam) 1.1.2 and previous versions reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux-pam linux-pam 1.0.0

linux-pam linux-pam 0.99.9.0

linux-pam linux-pam 0.99.6.0

linux-pam linux-pam 0.99.6.1

linux-pam linux-pam 0.99.1.0

linux-pam linux-pam 0.99.2.0

linux-pam linux-pam 0.99.2.1

linux-pam linux-pam 1.0.4

linux-pam linux-pam 1.0.1

linux-pam linux-pam 1.1.0

linux-pam linux-pam 0.99.5.0

linux-pam linux-pam 0.99.8.0

linux-pam linux-pam 0.99.8.1

linux-pam linux-pam 1.0.3

linux-pam linux-pam 0.99.6.2

linux-pam linux-pam 0.99.6.3

linux-pam linux-pam 0.99.3.0

linux-pam linux-pam 0.99.4.0

linux-pam linux-pam 0.99.10.0

linux-pam linux-pam 1.1.1

linux-pam linux-pam 1.0.2

linux-pam linux-pam 0.99.7.0

linux-pam linux-pam 0.99.7.1

linux-pam linux-pam

Vendor Advisories

Debian Bug report logs - #611136 CVE-2010-4708: pam_env reads env variables from user file by default Package: pam; Maintainer for pam is Steve Langasek <vorlon@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 25 Jan 2011 21:45:02 UTC Severity: important Tags: confirmed, patch, security, upstr ...

Github Repositories

kzn OS Built against macOS Mojave, Fedora 29 Cinnamon Prerequisites Linuxbrew/homebrew Initial Build mkdir ~/kzn curl -sSL githubcom/liamdawson/kzn/archive/mastertargz | tar -xz --directory="$HOME/kzn" --strip-components=1 ~/kzn/kzn cycle Env Specific Notes LightDM (Cinnamon) ~/pam_environment ~/pam_environment