CVE-2010-3430 describes a privilege-dropping flaw in the pam_env and pam_mail modules of Linux-PAM 1.1.2. This vulnerability stems from an incomplete fix for a previous issue, where the modules failed to perform necessary setfsgid and setgroups system calls. This oversight could allow local users to gain unauthorized access to sensitive information by exploiting unintended group permissions, for instance, through a symlink attack on a user's .pam_environment file. The vulnerability has a CVSS score of 4.7, indicating a medium severity. It requires local access and medium attack complexity, with the primary impact being a complete loss of confidentiality. There is no impact on integrity or availability. Despite its potential for information disclosure, there is no evidence of active exploitation, no known exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog. Community discussion and media coverage are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.2CPE matchmatch criteria | cpe:2.3:a:linux-pam:linux-pam:1.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.