Fedora 33: pam 2020-22532a1a81
Fedora 33: pam 2020-22532a1a81
fix CVE-2020-27780: authentication bypass when the user doesn't exist
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2020-22532a1a81 2020-11-28 02:02:44.955114 -------------------------------------------------------------------------------- Name : pam Product : Fedora 33 Version : 1.4.0 Release : 9.fc33 URL : https://www.linux-pam.org/ Summary : An extensible library which provides authentication for applications Description : PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. -------------------------------------------------------------------------------- Update Information: fix CVE-2020-27780: authentication bypass when the user doesn't exist -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 24 2020 Iker Pedrosa- 1.4.0-9 - fix CVE-2020-27780: authentication bypass when the user doesn't exist and root password is blank (#1901173) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1901094 - CVE-2020-27780 pam: authentication bypass when the user doesn't exist and root password is blank https://bugzilla.redhat.com/show_bug.cgi?id=1901094 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-22532a1a81' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it.