CVE-2010-4707: Medium severity Linux-PAM Linux-PAM vulnerability
The checkacl function in pamxauth.c in the pamxauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4707?
CVE-2010-4707 is regarded as a medium severity vulnerability, primarily causing potential denial of service.
How do I fix CVE-2010-4707?
To fix CVE-2010-4707, upgrade to a patched version of Linux-PAM that is later than 1.1.2.
What causes CVE-2010-4707?
CVE-2010-4707 is caused by the check_acl function in pam_xauth.c allowing verification of non-regular files.
Who is affected by CVE-2010-4707?
Local users of affected versions of the Linux-PAM module are the ones at risk of exploitation from CVE-2010-4707.
What are the affected versions for CVE-2010-4707?
CVE-2010-4707 affects Linux-PAM versions 1.1.2 and earlier, as well as some earlier specific versions.