CVE-2010-3431
Summary
| CVE | CVE-2010-3431 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-24 18:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435. |
Risk And Classification
Primary CVSS: v2.0 1.9 from [email protected]
AV:L/AC:M/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 641361 – (CVE-2010-3430, CVE-2010-3431) CVE-2010-3430 CVE-2010-3431 pam: pam_mail and pam_env incorrect privilege dropping | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| Security Advisory SA49711 - Gentoo update for pam - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| Gentoo Linux Documentation -- Linux-PAM: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| git.altlinux.org - pam.git/commit | af854a3a-2127-422b-91ae-364da2661108 | git.altlinux.org | |
| oss-security - Re: Minor security flaw with pam_xauth | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Patch |
| git.altlinux.org - pam.git/commit | MITRE | git.altlinux.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.