Description
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
CVSS Metrics
- Vector
- AV:L/AC:M/Au:N/C:C/I:N/A:N
- Access Vector
- local
- Access Cmplx
- medium
- Auth
- none
- Confidentiality
- complete
- Integrity
- none
- Availability
- none
- Weaknesses
- NVD-CWE-Other
Metadata
- Primary Vendor
- LINUX-PAM
- Published
- 1/24/2011
- Last Modified
- 4/11/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
linux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pam
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.