Vulnerability Database

289,782

Total vulnerabilities in the database

CVE-2010-3853

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

  • Published: Jan 24, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-3853
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.9
  • AV:L/AC:M/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
linux-pam / linux-pam 0.99.1.0 0.99.1.0.x
linux-pam / linux-pam 0.99.2.0 0.99.2.0.x
linux-pam / linux-pam 0.99.2.1 0.99.2.1.x
linux-pam / linux-pam 0.99.3.0 0.99.3.0.x
linux-pam / linux-pam 0.99.4.0 0.99.4.0.x
linux-pam / linux-pam 0.99.5.0 0.99.5.0.x
linux-pam / linux-pam 0.99.6.0 0.99.6.0.x
linux-pam / linux-pam 0.99.6.1 0.99.6.1.x
linux-pam / linux-pam 0.99.6.2 0.99.6.2.x
linux-pam / linux-pam 0.99.6.3 0.99.6.3.x
linux-pam / linux-pam 0.99.7.0 0.99.7.0.x
linux-pam / linux-pam 0.99.7.1 0.99.7.1.x
linux-pam / linux-pam 0.99.8.0 0.99.8.0.x
linux-pam / linux-pam 0.99.8.1 0.99.8.1.x
linux-pam / linux-pam 0.99.9.0 0.99.9.0.x
linux-pam / linux-pam 0.99.10.0 0.99.10.0.x
linux-pam / linux-pam 1.0.0 1.0.0.x
linux-pam / linux-pam 1.0.1 1.0.1.x
linux-pam / linux-pam 1.0.2 1.0.2.x
linux-pam / linux-pam 1.0.3 1.0.3.x
linux-pam / linux-pam 1.0.4 1.0.4.x
linux-pam / linux-pam 1.1.0 1.1.0.x
linux-pam / linux-pam 1.1.1 1.1.1.x
linux-pam / linux-pam - 1.1.2.x