CVE-2010-4706: Medium severity Linux-PAM Linux-PAM vulnerability
The pamsmclosesession function in pamxauth.c in the pamxauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pamxauth PAM check.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4706?
The severity of CVE-2010-4706 is considered high due to the potential for local users to delete unintended files.
How do I fix CVE-2010-4706?
To fix CVE-2010-4706, update your Linux-PAM installation to version 1.1.3 or later.
Which versions of Linux-PAM are affected by CVE-2010-4706?
CVE-2010-4706 affects Linux-PAM versions up to and including 1.1.2.
What impact does CVE-2010-4706 have on systems?
CVE-2010-4706 can allow local users to manipulate session files, leading to potentially undesired file deletions.
Is CVE-2010-4706 exploitable remotely?
CVE-2010-4706 is not exploitable remotely; it requires local access to the system.