Date:         Mon, 28 Jul 2008 16:19:23 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for coreutils on SL4.x i386/x86_64
Comments: To: "scientific-linux-errata@fnal.gov"
          

Synopsis:	Low: coreutils security update
Issue date:	2008-07-24
CVE Names:	CVE-2008-1946

The coreutils packages were found to not use the pam_succeed_if Pluggable
Authentication Module (PAM) correctly in the configuration file for the
"su" command. Any local user could use this command to change to a locked
or expired user account if the target account's password was known to the
user running "su". These updated packages, correctly, only allow the root
user to switch to locked or expired accounts using "su". (CVE-2008-1946)

SL 4.x

    SRPMS:
coreutils-5.2.1-31.8.el4.src.rpm
    i386:
coreutils-5.2.1-31.8.el4.i386.rpm
    x86_64:
coreutils-5.2.1-31.8.el4.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2008-1946 coreutils SL4.x i386/x86_64

Low: coreutils security update

Summary

Date:         Mon, 28 Jul 2008 16:19:23 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for coreutils on SL4.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov"          Synopsis:	Low: coreutils security updateIssue date:	2008-07-24CVE Names:	CVE-2008-1946The coreutils packages were found to not use the pam_succeed_if PluggableAuthentication Module (PAM) correctly in the configuration file for the"su" command. Any local user could use this command to change to a lockedor expired user account if the target account's password was known to theuser running "su". These updated packages, correctly, only allow the rootuser to switch to locked or expired accounts using "su". (CVE-2008-1946)SL 4.x    SRPMS:coreutils-5.2.1-31.8.el4.src.rpm    i386:coreutils-5.2.1-31.8.el4.i386.rpm    x86_64:coreutils-5.2.1-31.8.el4.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity