Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-4707

Опубликовано: 03 окт. 2010
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. This issue was addressed in the PAM packages in Red Hat Enterprise Linux 5 via RHSA-2010:0819 and in Red Hat Enterprise Linux 6 via RHSA-2010:0891. A future update may correct this issue in the PAM packages in Red Hat Enterprise Linux 4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4pamWill not fix
Red Hat Enterprise Linux 5pamFixedRHSA-2010:081901.11.2010
Red Hat Enterprise Linux 6pamFixedRHSA-2010:089116.11.2010

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=672486pam: pam_xauth: Does not check if certain ACL file is a regular file

EPSS

Процентиль: 20%
0.00062
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

nvd
больше 14 лет назад

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

debian
больше 14 лет назад

The check_acl function in pam_xauth.c in the pam_xauth module in Linux ...

github
около 3 лет назад

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

oracle-oval
больше 14 лет назад

ELSA-2010-0819: pam security update (MODERATE)

EPSS

Процентиль: 20%
0.00062
Низкий

2.1 Low

CVSS2