pam (1.1.2-2ubuntu8.2) natty-security; urgency=low

  * SECURITY UPDATE: multiple issues with lack of adequate privilege
    dropping
    - debian/patches/security-dropprivs.patch: introduce new privilege
      dropping code in libpam/pam_modutil_priv.c, libpam/Makefile.*,
      libpam/include/security/pam_modutil.h, libpam/libpam.map,
      modules/pam_env/pam_env.c, modules/pam_mail/pam_mail.c,
      modules/pam_xauth/pam_xauth.c.
    - CVE-2010-3430
    - CVE-2010-3431
    - CVE-2010-3435
    - CVE-2010-4706
    - CVE-2010-4707
  * SECURITY UPDATE: privilege escalation via incorrect environment
    - debian/patches/CVE-2010-3853.patch: use clean environment in
      modules/pam_namespace/pam_namespace.c.
    - CVE-2010-3853
  * debian/patches-applied/series: disable hurd_no_setfsuid patch, as it
    isn't needed for Ubuntu, and it needs to be rewritten to work with the
    massive privilege refactoring in the security patches.

Date: Thu, 19 May 2011 08:40:22 -0400
Changed-By: Marc Deslauriers <[email protected]>
Maintainer: Ubuntu Developers <[email protected]>
https://launchpad.net/ubuntu/natty/+source/pam/1.1.2-2ubuntu8.2
Format: 1.8
Date: Thu, 19 May 2011 08:40:22 -0400
Source: pam
Binary: libpam0g libpam-modules libpam-modules-bin libpam-runtime libpam0g-dev 
libpam-cracklib libpam-doc
Architecture: source
Version: 1.1.2-2ubuntu8.2
Distribution: natty-security
Urgency: low
Maintainer: Ubuntu Developers <[email protected]>
Changed-By: Marc Deslauriers <[email protected]>
Description: 
 libpam-cracklib - PAM module to enable cracklib support
 libpam-doc - Documentation of PAM
 libpam-modules - Pluggable Authentication Modules for PAM
 libpam-modules-bin - Pluggable Authentication Modules for PAM - helper binaries
 libpam-runtime - Runtime support for the PAM library
 libpam0g   - Pluggable Authentication Modules library
 libpam0g-dev - Development files for PAM
Changes: 
 pam (1.1.2-2ubuntu8.2) natty-security; urgency=low
 .
   * SECURITY UPDATE: multiple issues with lack of adequate privilege
     dropping
     - debian/patches/security-dropprivs.patch: introduce new privilege
       dropping code in libpam/pam_modutil_priv.c, libpam/Makefile.*,
       libpam/include/security/pam_modutil.h, libpam/libpam.map,
       modules/pam_env/pam_env.c, modules/pam_mail/pam_mail.c,
       modules/pam_xauth/pam_xauth.c.
     - CVE-2010-3430
     - CVE-2010-3431
     - CVE-2010-3435
     - CVE-2010-4706
     - CVE-2010-4707
   * SECURITY UPDATE: privilege escalation via incorrect environment
     - debian/patches/CVE-2010-3853.patch: use clean environment in
       modules/pam_namespace/pam_namespace.c.
     - CVE-2010-3853
   * debian/patches-applied/series: disable hurd_no_setfsuid patch, as it
     isn't needed for Ubuntu, and it needs to be rewritten to work with the
     massive privilege refactoring in the security patches.
Checksums-Sha1: 
 5b0c4c6466e67b3ef32488366dc4d0225e61dd93 2267 pam_1.1.2-2ubuntu8.2.dsc
 4a0a260fbd51f1a9c8b3edf1d63b117c8a39727e 332474 pam_1.1.2-2ubuntu8.2.diff.gz
Checksums-Sha256: 
 7a2cf7bf658f23b9c694387471969e5c41e98755e47a7bbe2441a367a509e130 2267 
pam_1.1.2-2ubuntu8.2.dsc
 7e3888573a5634ffb72a750b934f1da23e2d3b8a759220b8103c515944fd80d7 332474 
pam_1.1.2-2ubuntu8.2.diff.gz
Files: 
 c102d40047ebdac4596eeda737524e07 2267 libs optional pam_1.1.2-2ubuntu8.2.dsc
 5fa96f6d2b4ed7a8454618b28a255f70 332474 libs optional 
pam_1.1.2-2ubuntu8.2.diff.gz
Original-Maintainer: Steve Langasek <[email protected]>
-- 
Natty-changes mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/natty-changes

Reply via email to