The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pam | Jul 30, 2024 | Jan 24, 2011 |
| Gentoo Linux | — | Upgrade sys-libs/pam. | Oct 30, 2017 | Jan 24, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 3, 2010 |
| Ubuntu | — | Upgrade libpam-modules | Nov 8, 2024 | Jan 24, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub