Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2010-3316

The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.

  • Published: Jan 24, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-3316
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 3.3
  • AV:L/AC:M/Au:N/C:P/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
linux-pam / linux-pam 0.99.1.0 0.99.1.0.x
linux-pam / linux-pam 0.99.2.0 0.99.2.0.x
linux-pam / linux-pam 0.99.2.1 0.99.2.1.x
linux-pam / linux-pam 0.99.3.0 0.99.3.0.x
linux-pam / linux-pam 0.99.4.0 0.99.4.0.x
linux-pam / linux-pam 0.99.5.0 0.99.5.0.x
linux-pam / linux-pam 0.99.6.0 0.99.6.0.x
linux-pam / linux-pam 0.99.6.1 0.99.6.1.x
linux-pam / linux-pam 0.99.6.2 0.99.6.2.x
linux-pam / linux-pam 0.99.6.3 0.99.6.3.x
linux-pam / linux-pam 0.99.7.0 0.99.7.0.x
linux-pam / linux-pam 0.99.7.1 0.99.7.1.x
linux-pam / linux-pam 0.99.8.0 0.99.8.0.x
linux-pam / linux-pam 0.99.8.1 0.99.8.1.x
linux-pam / linux-pam 0.99.9.0 0.99.9.0.x
linux-pam / linux-pam 0.99.10.0 0.99.10.0.x
linux-pam / linux-pam 1.0.0 1.0.0.x
linux-pam / linux-pam 1.0.1 1.0.1.x
linux-pam / linux-pam 1.0.2 1.0.2.x
linux-pam / linux-pam 1.0.3 1.0.3.x
linux-pam / linux-pam 1.0.4 1.0.4.x
linux-pam / linux-pam 1.1.0 1.1.0.x
linux-pam / linux-pam - 1.1.1.x