CVE-2010-3430
Summary
| CVE | CVE-2010-3430 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-24 18:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435. |
Risk And Classification
Primary CVSS: v2.0 4.7 from [email protected]
AV:L/AC:M/Au:N/C:C/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 641361 – (CVE-2010-3430, CVE-2010-3431) CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| Security Advisory SA49711 - Gentoo update for pam - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| Gentoo Linux Documentation -- Linux-PAM: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| git.altlinux.org - pam.git/commit | af854a3a-2127-422b-91ae-364da2661108 | git.altlinux.org | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| git.altlinux.org - pam.git/commit | MITRE | git.altlinux.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.