CVE-2010-4708: High severity Linux-PAM Linux-PAM vulnerability
The pamenv module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pamenvironment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pamenv PAM check.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4708?
CVE-2010-4708 is classified as a moderate severity vulnerability due to the potential for local users to exploit unintended environment variables.
How do I fix CVE-2010-4708?
To mitigate CVE-2010-4708, upgrade to Linux-PAM version 1.1.3 or later where the vulnerability is addressed.
Who is affected by CVE-2010-4708?
CVE-2010-4708 affects users of Linux-PAM versions up to and including 1.1.2.
What kind of exploitation can occur with CVE-2010-4708?
Exploitation of CVE-2010-4708 allows local users to run programs with modified environment variables by manipulating the .pam_environment file.
Is CVE-2010-4708 limited to a specific Linux distribution?
CVE-2010-4708 is not limited to a specific distribution, as it affects the Linux-PAM module used across various distributions.