CVE-2010-4708

The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
linux-pamlinux-pam
𝑥
≤ 1.1.2
linux-pamlinux-pam
0.99.1.0
linux-pamlinux-pam
0.99.2.0
linux-pamlinux-pam
0.99.2.1
linux-pamlinux-pam
0.99.3.0
linux-pamlinux-pam
0.99.4.0
linux-pamlinux-pam
0.99.5.0
linux-pamlinux-pam
0.99.6.0
linux-pamlinux-pam
0.99.6.1
linux-pamlinux-pam
0.99.6.2
linux-pamlinux-pam
0.99.6.3
linux-pamlinux-pam
0.99.7.0
linux-pamlinux-pam
0.99.7.1
linux-pamlinux-pam
0.99.8.0
linux-pamlinux-pam
0.99.8.1
linux-pamlinux-pam
0.99.9.0
linux-pamlinux-pam
0.99.10.0
linux-pamlinux-pam
1.0.0
linux-pamlinux-pam
1.0.1
linux-pamlinux-pam
1.0.2
linux-pamlinux-pam
1.0.3
linux-pamlinux-pam
1.0.4
linux-pamlinux-pam
1.1.0
linux-pamlinux-pam
1.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pam
bookworm
1.5.2-6+deb12u1
fixed
bullseye
1.4.0-9+deb11u1
fixed
lenny
no-dsa
sid
1.5.3-7
fixed
squeeze
no-dsa
trixie
1.5.3-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pam
dapper
ignored
hardy
ignored
karmic
ignored
lucid
ignored
maverick
ignored
natty
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
pam
RHEL 6
0:1.1.1-4.el6_0.1
fixed
pam-devel
RHEL 6
0:1.1.1-4.el6_0.1
fixed