---
title: "CVE-2010-3435\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-3435?format=md
keywords: index, follow
---

# CVE-2010-3435

Publication date 24 January 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The (1) pam\_env and (2) pam\_mail modules in Linux-PAM (aka pam) before
1.1.2 use root privileges during read access to files and directories that
belong to arbitrary user accounts, which might allow local users to obtain
sensitive information by leveraging this filesystem activity, as
demonstrated by a symlink attack on the .pam\_environment file in a user's
home directory.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2010-3435?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| pam | 11.04 natty | Fixed 1.1.2-2ubuntu8.2 |
| 10.10 maverick | Fixed 1.1.1-4ubuntu2.2 |
| 10.04 LTS lucid | Fixed 1.1.1-2ubuntu5.2 |
| 9.10 karmic | Ignored end of life |
| 8.04 LTS hardy | Fixed 0.99.7.1-5ubuntu6.3 |
| 6.06 LTS dapper | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2010-3435?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

All patched below are needed, only two first were included in
1.1.2, and second introduced CVE-2010-3430 and CVE-2010-3431,
which is fixed by second patch.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| pam | * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=60530da87ddd4ce280fbd5cae182dc7ac3b1a154> * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=06f882f30092a39a1db867c9744b2ca8d60e4ad6> * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=4e8357e4609be470ee5214be01e2d1d0e688f580> * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=ffe7058c70253d574b1963c7c93002bd410fddc9> * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=05dafc06cd3dfeb7c4b24942e4e1ae33ff75a123> * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=cee7448470a6fe895269c760134dc95d6952d260> * Upstream:   <http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=843807a3a90f52e7538be756616510730a24739a> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3435)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-3435)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-3435)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-3435)

### Related Ubuntu Security Notices (USN)

+ [USN-1140-1](https://usn.ubuntu.com/USN-1140-1)
+ PAM vulnerabilities
+ 30 May 2011

### Other references

* <http://thread.gmane.org/gmane.comp.security.oss.general/3311/focus=3534>
* <https://www.cve.org/CVERecord?id=CVE-2010-3435>
