header-logo
Suggest Exploit
vendor:
Ubuntu Linux
by:
Kristian Erik Hermansen
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Ubuntu Linux
Affected Version From: Ubuntu 9.10
Affected Version To: Ubuntu 10.04 LTS
Patch Exists: YES
Related CWE: CVE-2010-0832
CPE: o:ubuntu:ubuntu_linux:10.04
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 10.04 LTS (Lucid Lynx)
2010

Ubuntu PAM MOTD file tampering (privilege escalation)

This exploit allows an attacker to gain root privileges by tampering with the PAM MOTD file. The attacker can create a symbolic link to the file they wish to tamper with and then log back into their shell or re-ssh to make PAM call the vulnerable MOTD code. The file will then be owned by the user.

Mitigation:

The user should install the latest version of libpam and update their system regularly.
Source

Exploit-DB raw data: