Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-4707 | First vendor Publication | 2011-01-24 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.9 | Attack Range | Local |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4707 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:13730 | |||
Oval ID: | oval:org.mitre.oval:def:13730 | ||
Title: | USN-1140-2 -- pam regression | ||
Description: | pam: Pluggable Authentication Modules Details: USN-1140-1 fixed vulnerabilities in PAM. A regression was found that caused cron to stop working with a "Module is unknown" error. As a result, systems configured with automatic updates will not receive updates until cron is restarted, these updates are installed or the system is rebooted. This update fixes the problem. We apologize for the inconvenience. Original advisory The USN-1140-1 PAM update caused cron to stop working. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1140-2 CVE-2009-0887 CVE-2010-3316 CVE-2010-3430 CVE-2010-3431 CVE-2010-3435 CVE-2010-3853 CVE-2010-4706 CVE-2010-4707 | Version: | 5 |
Platform(s): | Ubuntu 10.10 Ubuntu 8.04 Ubuntu 10.04 | Product(s): | pam |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:13977 | |||
Oval ID: | oval:org.mitre.oval:def:13977 | ||
Title: | USN-1140-1 -- pam vulnerabilities | ||
Description: | pam: Pluggable Authentication Modules An attacker could cause PAM to read or delete arbitrary files or cause it to crash. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1140-1 CVE-2009-0887 CVE-2010-3316 CVE-2010-3430 CVE-2010-3431 CVE-2010-3435 CVE-2010-3853 CVE-2010-4706 CVE-2010-4707 | Version: | 5 |
Platform(s): | Ubuntu 10.10 Ubuntu 8.04 Ubuntu 10.04 | Product(s): | pam |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:22164 | |||
Oval ID: | oval:org.mitre.oval:def:22164 | ||
Title: | RHSA-2010:0819: pam security update (Moderate) | ||
Description: | The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2010:0819-01 CESA-2010:0819 CVE-2010-3316 CVE-2010-3435 CVE-2010-3853 CVE-2010-4707 | Version: | 55 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | pam |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:23155 | |||
Oval ID: | oval:org.mitre.oval:def:23155 | ||
Title: | ELSA-2010:0819: pam security update (Moderate) | ||
Description: | The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2010:0819-01 CVE-2010-3316 CVE-2010-3435 CVE-2010-3853 CVE-2010-4707 | Version: | 21 |
Platform(s): | Oracle Linux 5 | Product(s): | pam |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:27934 | |||
Oval ID: | oval:org.mitre.oval:def:27934 | ||
Title: | DEPRECATED: ELSA-2010-0819 -- pam security update (moderate) | ||
Description: | [0.99.6.2-6.2] - fix insecure dropping of priviledges in pam_xauth and pam_mail - CVE-2010-3316 (#637898), CVE-2010-3435 (#641335) - fix insecure executing of scripts with user supplied environment variables in pam_namespace - CVE-2010-3853 (#643043) | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2010-0819 CVE-2010-3316 CVE-2010-3435 CVE-2010-3853 CVE-2010-4707 | Version: | 4 |
Platform(s): | Oracle Linux 5 | Product(s): | pam |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-08-10 | Name : Gentoo Security Advisory GLSA 201206-31 (pam) File : nvt/glsa_201206_31.nasl |
2011-06-06 | Name : Ubuntu Update for pam USN-1140-1 File : nvt/gb_ubuntu_USN_1140_1.nasl |
2011-06-06 | Name : Ubuntu Update for pam USN-1140-2 File : nvt/gb_ubuntu_USN_1140_2.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
70653 | Linux-PAM pam_xauth Module pam_xauth.c check_acl Function Special ACL File Lo... Linux-PAM contains a flaw that may allow a local denial of service. The issue is triggered when the 'check_acl' function in 'pam_xauth.c' in the 'pam_xauth' module fails to verify that a ACL file is a regular file, allowing a local user to use a special file to cause a denial of service. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2010-0819.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2010-0891.nasl - Type : ACT_GATHER_INFO |
2012-06-26 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201206-31.nasl - Type : ACT_GATHER_INFO |
2011-06-13 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-1140-1.nasl - Type : ACT_GATHER_INFO |
2011-06-13 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1140-2.nasl - Type : ACT_GATHER_INFO |
2010-11-24 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2010-0819.nasl - Type : ACT_GATHER_INFO |
2010-11-18 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0891.nasl - Type : ACT_GATHER_INFO |
2010-11-02 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0819.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:18 |
|
2024-11-28 12:24:00 |
|
2024-11-05 01:15:14 |
|
2023-11-07 21:47:30 |
|
2021-05-05 01:07:48 |
|
2021-05-04 12:13:14 |
|
2021-04-22 01:13:43 |
|
2020-12-23 01:06:10 |
|
2020-05-23 01:43:26 |
|
2020-05-23 00:27:17 |
|
2019-01-03 21:18:53 |
|
2017-08-17 09:23:13 |
|
2016-04-26 20:19:26 |
|
2014-02-17 10:59:07 |
|
2013-05-10 23:39:15 |
|