Back

MEDIUM

pam: pam_xauth: Does not check if certain ACL file is a regular file

Published Jan 24, 2011

Description

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

Affected products

Remediation

Red Hat statement

The Red Hat Security Response Team has rated this issue as having low security impact. This issue was addressed in the PAM packages in Red Hat Enterprise Linux 5 via RHSA-2010:0819 and in Red Hat Enterprise Linux 6 via RHSA-2010:0891. A future update may correct this issue in the PAM packages in Red Hat Enterprise Linux 4.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 24, 2011
Updated Aug 7, 2024
Reserved Jan 24, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Oct 3, 2010