CVE-2010-3435

Source
https://cve.org/CVERecord?id=CVE-2010-3435
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2010-3435.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2010-3435
Downstream
Withdrawn
2026-01-27T04:10:27.110597Z
Published
2011-01-24T18:00:02Z
Modified
2026-01-27T04:10:27.110597Z
Summary
[none]
Details

The (1) pamenv and (2) pammail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory.

References

Affected packages