Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Authentication Fix for Scientific Linux SL3.x pam_krb5 Errata 13-42-01

Scientific Large Esm H446
Low: pam_krb5 bug fix update
Date: Fri, 15 Aug 2008 13:42:01 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA for pam_krb5 on SL3.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 

Synopsis:	Low: pam_krb5 bug fix update
Issue date:	2008-08-04

These updated pam-krb5 packages fix a bug which caused user authentication
to fail under certain circumstances. When authenticating a user, if the
user's password was expired, the module would attempt to obtain
password-changing credentials in order to verify the user's password. When
the module was configured to validate credentials, it would incorrectly
attempt to validate the password-changing credentials, which cannot be
validated in the way that a ticket-granting ticket can. In these updated
packages, an exception is made in this case, thus resolving the issue.

SL 3.0.x

 SRPMS:
pam_krb5-1.81-1.src.rpm
 i386:
pam_krb5-1.81-1.i386.rpm
 x86_64:
pam_krb5-1.81-1.i386.rpm
pam_krb5-1.81-1.x86_64.rpm

-Connie Sieh
-Troy Dawson