Security Advisory

CVE-2010-3853

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-01-24 17:00:00
Last updated 2024-08-07 03:26:12
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.