Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

openSUSE 11.4: openSUSE-SU-2011:1204-1 Important: pam DoS Fix

opensuse
Calendar Grey November 2, 2011
Dist Opensuse Esm H88
A critical patch for Fedora has been released tackling buffer overflow vulnerabilities and Denial of Service threats in the authentication module.
An update that fixes two vulnerabilities is now available

Description

The pam_env module is vulnerable to a stack overflow

(CVE-2011-3148) and a DoS condition (CVE-2011-3149) when

parsing users .pam_environment files.

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch pam-5330

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

pam-1.1.3-4.9.1

pam-devel-1.1.3-4.9.1

pam-doc-1.1.3-4.9.1

- openSUSE 11.4 (x86_64):

pam-32bit-1.1.3-4.9.1

pam-devel-32bit-1.1.3-4.9.1

References

https://www.suse.com/security/cve/CVE-2011-3148.html

https://www.suse.com/security/cve/CVE-2011-3149.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2011:1204-1
Rating: important
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here