VDB

DEBIAN-CVE-2010-3435

DEBIAN-CVE-2010-3435 PUBLISHED CVSS 6.900000095367432 MEDIUM

The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.

Risk Scores

CVSS v4.0
6.900000095367432
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:12pam0, 0, 0
Debian:14pam0, 0, 0
Debian:11pam0, 0, 0
Debian:13pam0, 0, 0

Timeline

  • Jan 24, 2011 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›