Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
BID:43487
Info
Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
| Bugtraq ID: | 43487 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-3430 CVE-2010-3431 CVE-2010-3435 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 24 2010 12:00AM |
| Updated: | May 07 2015 05:03PM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
VMWare ESX Server 4.1 VMWare ESX Server 4.0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Pardus Linux 2009 0 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Linux-PAM Linux-PAM 1.1.1 Juniper CTPView 4.6 Juniper CTPView 4.5 Juniper CTPView 4.4 Juniper CTPView 4.3 Juniper CTPView 4.2 Gentoo Linux Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya IQ 5.1 Avaya IQ 5 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform SP1.1 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 4.2.3 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.6 Avaya Aura Application Enablement Services 3.1.5 Avaya Aura Application Enablement Services 3.1.4 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Avaya Aura Application Enablement Services 3.0 |
| Not Vulnerable: |
VMWare ESX Server 4.0 ESX400-201103404 Linux-PAM Linux-PAM 1.1.2 Juniper CTPView 7.0R1 Avaya IQ 5.2 Avaya Aura System Platform 6.0 SP3 Avaya Aura Application Enablement Services 5.2.3 |
Discussion
Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
Linux-PAM 'pam_env' and 'pam_mail' modules are prone to local privilege-escalation vulnerabilities and a security-bypass vulnerability.
Local attackers may exploit these issues to gain elevated privileges, which can lead to a complete compromise of an affected computer.
Versions prior to Linux-PAM 1.1.2 are vulnerable.
Linux-PAM 'pam_env' and 'pam_mail' modules are prone to local privilege-escalation vulnerabilities and a security-bypass vulnerability.
Local attackers may exploit these issues to gain elevated privileges, which can lead to a complete compromise of an affected computer.
Versions prior to Linux-PAM 1.1.2 are vulnerable.
Exploit / POC
Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1 x86_64
Mandriva Linux Mandrake 2010.0
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2009.1
Mandriva Linux Mandrake 2009.1 x86_64
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva lib64pam-devel-1.1.1-2.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64pam0-1.1.1-2.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-1.1.1-2.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-1.1.1-2.1mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0
-
Mandriva libpam-devel-1.1.0-6.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libpam0-1.1.0-6.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-1.1.0-6.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-1.1.0-6.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva lib64pam-devel-0.99.8.1-16.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64pam0-0.99.8.1-16.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-0.99.8.1-16.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-0.99.8.1-16.2mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1
-
Mandriva libpam-devel-0.99.8.1-20.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libpam0-0.99.8.1-20.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-0.99.8.1-20.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-0.99.8.1-20.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva lib64pam-devel-0.99.8.1-20.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64pam0-0.99.8.1-20.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-0.99.8.1-20.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-0.99.8.1-20.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva lib64pam-devel-0.99.8.1-16.2mdvmes5.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64pam0-0.99.8.1-16.2mdvmes5.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-0.99.8.1-16.2mdvmes5.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-0.99.8.1-16.2mdvmes5.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva libpam-devel-0.99.8.1-16.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libpam0-0.99.8.1-16.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-0.99.8.1-16.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-0.99.8.1-16.2mdvmes5.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva lib64pam-devel-1.1.0-6.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64pam0-1.1.0-6.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-1.1.0-6.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva pam-doc-1.1.0-6.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
References
Linux-PAM 'pam_env' and 'pam_mail' Modules Multiple Vulnerabilities
References:
References:
- PAM Repository (Thorsten Kukuk )
- pam_env and pam_mail Bug Report (Solar Designer)
- 2014-11 Security Bulletin: CTPView: Multiple Security vulnerabilities resolved b (Juniper)
- ASA-2010-331 pam security update (RHSA-2010-0819) (Avaya)
- VMWare Security Advisory: VMSA-2011-0004 (VMWare)