Back to search
CVE-2010-4706
Published: Jan 24, 2011
Modified: Aug 7, 2024
PUBLISHED
Description
The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
GLSA-201206-31
vendor-advisory
x_refsource_GENTOO
[oss-security] 20101004 Re: Minor security flaw with pam_xauth
mailing-list
x_refsource_MLIST
46045
vdb-entry
x_refsource_BID
49711
third-party-advisory
x_refsource_SECUNIA
linuxpam-pamsmclosesession-weak-security(65035)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now