« List of all CVEs

CVE-2010-4706

Published: 1/24/2011 Last updated: 8/7/2024 Reserved: 1/24/2011

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-pam pam

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (12)