Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3853

Опубликовано: 22 окт. 2010
Источник: redhat
CVSS2: 6.2
EPSS Низкий

Описание

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3pamNot affected
Red Hat Enterprise Linux 4pamNot affected
Red Hat Enterprise Linux 5pamFixedRHSA-2010:081901.11.2010
Red Hat Enterprise Linux 6pamFixedRHSA-2010:089116.11.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=643043pam: pam_namespace executes namespace.init with service's environment

EPSS

Процентиль: 38%
0.00161
Низкий

6.2 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

nvd
больше 14 лет назад

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

debian
больше 14 лет назад

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) bef ...

github
около 3 лет назад

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

oracle-oval
больше 14 лет назад

ELSA-2010-0819: pam security update (MODERATE)

EPSS

Процентиль: 38%
0.00161
Низкий

6.2 Medium

CVSS2