PublicDateAtUSN: 2011-01-24 Candidate: CVE-2010-4707 PublicDate: 2011-01-24 19:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4707 https://ubuntu.com/security/notices/USN-1140-1 Description: The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file. Ubuntu-Description: Notes: sbeattie> pam_xauth not enabled in the default install mdeslaur> see complete patch list in CVE-2010-3435 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611136 Priority: low Discovered-by: Assigned-to: CVSS: Patches_pam: upstream: http://git.altlinux.org/people/ldv/packages/?p=pam.git;a=commit;h=ffe7058c70253d574b1963c7c93002bd410fddc9 upstream_pam: released (1.1.3) dapper_pam: ignored (reached end-of-life) hardy_pam: released (0.99.7.1-5ubuntu6.3) karmic_pam: ignored (reached end-of-life) lucid_pam: released (1.1.1-2ubuntu5.2) maverick_pam: released (1.1.1-4ubuntu2.2) natty_pam: released (1.1.2-2ubuntu8.2) devel_pam: released (1.1.3-1ubuntu2)