CVE-2010-3431

The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the .pam_environment file in a user's home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.

Published: 2011-01-24 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-3431 is rated Low Risk (14.7/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.07%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2010-3431

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.04% 0.07% +0.03%
2 2023-03-07 1.55% 0.04% -1.50%
3 2022-02-04 1.55%

Full EPSS history (3 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-3431

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
1.9 2.0 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.4 2.9 [email protected]

Weakness enumeration for CVE-2010-3431

OS Trackers for CVE-2010-3431

vendor priority summary link
debian low CVE-2010-3431 low priority: Debian including 1 source packages (pam), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2010-3431
gentoo high CVE-2010-3431: 1 GLSA(s) (201206-31), 1 atom(s) (sys-libs/pam); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-3431
redhat medium https://access.redhat.com/security/cve/CVE-2010-3431
suse low CVE-2010-3431 severity low: SUSE including 44 source package names (pam-1.1.8-11.57, pam-1.1.8-14.1, …), 71 product×package rows across 29 product lines (SUSE Linux Enterprise Desktop 12, SUSE Linux Enterprise Desktop 12 SP1, … (29 product lines)): Fixed 71. https://www.suse.com/security/cve/CVE-2010-3431/
ubuntu medium CVE-2010-3431 medium priority: Ubuntu including 1 source packages (pam), 7 status rows across 7 suites (dapper, hardy, karmic, lucid, maverick, natty, upstream): released 5, ignored 2. https://ubuntu.com/security/CVE-2010-3431

Affected software / configurations for CVE-2010-3431

Vendor Product Version Raw CPE
linux-pam linux-pam 1.1.2 cpe:2.3:a:linux-pam:linux-pam:1.1.2:*:*:*:*:*:*:*

References for CVE-2010-3431

URL Tags
http://git.altlinux.org/people/ldv/packages/?p=pam.git%3Ba=commit%3Bh=843807a3a90f52e7538be756616510730a24739a
http://openwall.com/lists/oss-security/2010/09/21/10 Patch
http://openwall.com/lists/oss-security/2010/09/21/3 Patch
http://openwall.com/lists/oss-security/2010/09/21/8 Patch
http://openwall.com/lists/oss-security/2010/09/21/9
http://openwall.com/lists/oss-security/2010/09/27/10
http://openwall.com/lists/oss-security/2010/09/27/4 Patch
http://openwall.com/lists/oss-security/2010/09/27/5
http://openwall.com/lists/oss-security/2010/09/27/7
http://openwall.com/lists/oss-security/2010/10/03/1 Patch
http://openwall.com/lists/oss-security/2010/10/25/2 Patch
http://secunia.com/advisories/49711
http://security.gentoo.org/glsa/glsa-201206-31.xml
http://www.openwall.com/lists/oss-security/2010/09/21/11 Patch
http://www.openwall.com/lists/oss-security/2010/09/24/2
https://bugzilla.redhat.com/show_bug.cgi?id=641361 Patch
cvelogic Threat Intelligence