HomeLinux-PamCVE-2010-3435

CVE-2010-3435

UNKNOWN
4.7CVSS
Published: 2011-01-24
Updated: 2025-04-11
AI Analysis

Description

The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.

CVSS Metrics

Vector
AV:L/AC:M/Au:N/C:C/I:N/A:N
Access Vector
local
Access Cmplx
medium
Auth
none
Confidentiality
complete
Integrity
none
Availability
none
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
LINUX-PAM
Published
1/24/2011
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

linux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pamlinux-pam : linux-pam

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2010-3435 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com