The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade pam-develUpgrade pam | Dec 1, 2016 | Jan 24, 2011 |
| Debian | — | Upgrade pam | Jul 30, 2024 | Jan 24, 2011 |
| Gentoo Linux | — | Upgrade sys-libs/pam. | Oct 30, 2017 | Jan 24, 2011 |
| Oracle_linux | — | Upgrade pamUpgrade pam-devel | Oct 16, 2024 | Jan 24, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 20, 2010 |
| Suse | — | Upgrade pam-x86Upgrade pam-32bitUpgrade pam-devel-32bitUpgrade pamUpgrade pam-devel-64bitUpgrade pam-develUpgrade pam-docUpgrade pam-64bitUpgrade sap-aio-release | Feb 17, 2015 | Jan 24, 2011 |
| Ubuntu | — | Upgrade libpam-modules | Nov 8, 2024 | Jan 24, 2011 |
| Vmsa 2011 0004 | — | Upgrade VMware ESX 4.0 to build number 360236Upgrade VMware ESX 4.1 to build number 381591 | Mar 10, 2011 | Jan 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub