This looks fixed in raring, precise, oneiric, and lucid:
$ grep -r env.*run-parts:
./pam-1.1.3/debian/patches-applied/update-motd:+ if
(!system("/usr/bin/env -i
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin run-parts
--lsbsysinit /etc/update-motd.d > /var/run/motd.new"))
./pam-1.1.3/debian/patches-applied/update-motd:+ if
(!system("/usr/bin/env -i
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin run-parts
--lsbsysinit /etc/update-motd.d > /var/run/motd.new"))
./pam-1.1.3/debian/patches-applied/update-motd:+ if
(!system("/usr/bin/env -i
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin run-parts
--lsbsysinit /etc/update-motd.d > /var/run/motd.new"))
pam-1.1.1/debian/patches-applied/update-motd:+ if (!system("/usr/bin/env -i
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
/bin/run-parts --lsbsysinit /etc/update-motd.d > /var/run/motd.new"))
** Changed in: pam (Ubuntu Precise)
Status: Triaged => Fix Released
** Changed in: pam (Ubuntu Oneiric)
Status: Triaged => Fix Released
** Changed in: pam (Ubuntu)
Status: Triaged => Fix Released
** Changed in: pam (Ubuntu Lucid)
Status: Triaged => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/610125
Title:
pam_motd runs commands as root with unsanitised environment
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/pam/+bug/610125/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs