Linux PAM contains a flaw that may allow an attacker to prevent the pam_xauth module from correctly dropping privileges. The issue is triggered when RLIMIT_NPROC is breached for the target user when pam_xauth makes a call to setuid() without checking the return value.
Classification
Location:
Local Access Required
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified,
Uncoordinated Disclosure
OSVDB:
Authentication Required,
Security Software
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, the developers have released a patch to address this vulnerability.