CVE-2010-3435
Last modified
CVE-2010-3435 is a vulnerability of currently unknown severity. The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux-Pam | Linux-Pam | <= 1.1.1 |
| Linux-Pam | Linux-Pam | 0.99.1.0 |
| Linux-Pam | Linux-Pam | 0.99.2.0 |
| Linux-Pam | Linux-Pam | 0.99.2.1 |
| Linux-Pam | Linux-Pam | 0.99.3.0 |
| Linux-Pam | Linux-Pam | 0.99.4.0 |
| Linux-Pam | Linux-Pam | 0.99.5.0 |
| Linux-Pam | Linux-Pam | 0.99.6.0 |
| Linux-Pam | Linux-Pam | 0.99.6.1 |
| Linux-Pam | Linux-Pam | 0.99.6.2 |
| Linux-Pam | Linux-Pam | 0.99.6.3 |
| Linux-Pam | Linux-Pam | 0.99.7.0 |
| Linux-Pam | Linux-Pam | 0.99.7.1 |
| Linux-Pam | Linux-Pam | 0.99.8.0 |
| Linux-Pam | Linux-Pam | 0.99.8.1 |
| Linux-Pam | Linux-Pam | 0.99.9.0 |
| Linux-Pam | Linux-Pam | 0.99.10.0 |
| Linux-Pam | Linux-Pam | 1.0.0 |
| Linux-Pam | Linux-Pam | 1.0.1 |
| Linux-Pam | Linux-Pam | 1.0.2 |
| Linux-Pam | Linux-Pam | 1.0.3 |
| Linux-Pam | Linux-Pam | 1.0.4 |
| Linux-Pam | Linux-Pam | 1.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3435?
How severe is CVE-2010-3435?
How do I fix CVE-2010-3435?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3429flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used…
- CVE-2010-3430The privilege-dropping implementation in the (1) pam_env and…
- CVE-2010-3431The privilege-dropping implementation in the (1) pam_env and…
- CVE-2010-3432The sctp_packet_config function in net/sctp/output.c in the …
- CVE-2010-3433The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 bef…
- CVE-2010-3434Buffer overflow in the find_stream_bounds function in pdf.c …
- CVE-2010-3436fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remo…
- CVE-2010-3437Integer signedness error in the pkt_find_dev_from_minor func…
- CVE-2010-3438libpoe-component-irc-perl before v6.32 does not remove carri…9.8
- CVE-2010-3439It is possible to cause a DoS condition by causing the serve…6.5
- CVE-2010-3440babiloo 2.0.9 before 2.0.11 creates temporary files with pre…5.5
- CVE-2010-3441Multiple buffer overflows in abcm2ps before 5.9.12 might all…
Are you affected by CVE-2010-3435?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
