Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Fri, 15 Aug 2008 13:42:01 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for pam_krb5 on SL3.x i386/x86_64 Comments: To: " This email address is being protected from spambots. You need JavaScript enabled to view it. "Synopsis: Low: pam_krb5 bug fix update Issue date: 2008-08-04 These updated pam-krb5 packages fix a bug which caused user authentication to fail under certain circumstances. When authenticating a user, if the user's password was expired, the module would attempt to obtain password-changing credentials in order to verify the user's password. When the module was configured to validate credentials, it would incorrectly attempt to validate the password-changing credentials, which cannot be validated in the way that a ticket-granting ticket can. In these updated packages, an exception is made in this case, thus resolving the issue. SL 3.0.x SRPMS: pam_krb5-1.81-1.src.rpm i386: pam_krb5-1.81-1.i386.rpm x86_64: pam_krb5-1.81-1.i386.rpm pam_krb5-1.81-1.x86_64.rpm -Connie Sieh -Troy Dawson