Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Debian: DSA 659-1 Urgent Update for Libpam-Radius-Auth Info Leak

debian
Calendar Grey January 26, 2005
Scroller Debian
Ubuntu Security Notice USN-1234-1 concerns a denial of service and buffer overflow vulnerability in libpam-xyz.
Two problems have been discovered in the libpam-radius-auth package, the PAM RADIUS authentication module

Summary


The Debian package accidently installed its configuration file
/etc/pam_radius_auth.conf world-readable. Since it may possibly
contain secrets all local users are able to read them if the
administrator hasn't adjusted file permissions. This problem is
Debian specific.

CAN-2005-0108

Leon Juranic discoverd an integer underflow in the mod_auth_radius
module for Apache which is also present in libpam-radius-auth.

For the stable distribution (woody) these problems have been fixed in
version 1.3.14-1.3.

For the unstable distribution (sid) these problems have been fixed in
version 1.3.16-3.

We recommend that you upgrade your libpam-radius-auth package.


Upgrade Instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.