SCIENTIFIC-LINUX-ERRATA Archives

July 2008

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Mon, 28 Jul 2008 16:19:23 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (23 lines)
Synopsis:	Low: coreutils security update
Issue date:	2008-07-24
CVE Names:	CVE-2008-1946

The coreutils packages were found to not use the pam_succeed_if Pluggable
Authentication Module (PAM) correctly in the configuration file for the
"su" command. Any local user could use this command to change to a locked
or expired user account if the target account's password was known to the
user running "su". These updated packages, correctly, only allow the root
user to switch to locked or expired accounts using "su". (CVE-2008-1946)

SL 4.x

    SRPMS:
coreutils-5.2.1-31.8.el4.src.rpm
    i386:
coreutils-5.2.1-31.8.el4.i386.rpm
    x86_64:
coreutils-5.2.1-31.8.el4.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2