Update to new minor upstream release. Minor security issue fixes and bug fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3231 2009-04-02 16:29:22 --------------------------------------------------------------------------------Name : pam Product : Fedora 9 Version : 1.0.4 Release : 4.fc9 URL : Summary : A security tool which provides authentication for applications Description : PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. --------------------------------------------------------------------------------Update Information: Update to new minor upstream release. Minor security issue fixes and bug fixes. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 30 2009 Tomas Mraz 1.0.4-4 - replace libtool to drop unneeded /lib64 rpath * Thu Mar 26 2009 Tomas Mraz 1.0.4-3 - replace all std descriptors when calling helpers (#491471) * Tue Mar 17 2009 Tomas Mraz 1.0.4-2 - update to new upstream minor release (bugfixes and minor security fixes) - drop tests for not pulling in libpthread (as NPTL should be safe) * Tue Sep 23 2008 Tomas Mraz 1.0.2-2 - new password quality checks in pam_cracklib - report failed logins from btmp in pam_lastlog - allow larger groups in modutil functions - fix leaked file descriptor in pam_tally * Wed May 21 2008 Tomas Mraz 1.0.1-4 - pam_namespace: allow safe creation of directories owned by user (#437116) - pam_unix: fix multiple error prompts on password change (#443872) * Tue May 20 2008 Tomas Mraz 1.0.1-3 - pam_selinux: add env_params option which will be used by OpenSSH - fix build with new autoconf --------------------------------------------------------------------------------References: [ 1 ] Bug #489932 - CVE-2009-0887 pam:integer signedness error in _pam_StrTok() https://bugzilla.redhat.com/show_bug.cgi?id=489932 [ 2 ] Bug #487216 - CVE-2009:0579 pam: MINDAYS not respected by pam for password changing https://bugzilla.redhat.com/show_bug.cgi?id=487216 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update pam' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
This update should fix potential problems with auditing in pam when used on systems with kernels without audit compiled in.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-799 2005-09-06 ---------------------------------------------------------------------Product : Fedora Core 4 Name : pam Version : 0.79 Release : 9.5 Summary : A security tool which provides authentication for applications. Description : PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. ---------------------------------------------------------------------Update Information: This update should fix potential problems with auditing in pam when used on systems with kernels without audit compiled in. ---------------------------------------------------------------------* Wed Aug 24 2005 Tomas Mraz 0.79-9.5 - add option to pam_loginuid to require auditd - don't fail in audit code when audit is not compiled in on the newest kernels (#166422) ---------------------------------------------------------------------This update can be downloaded from: 429c2170f7665f14ba91dbe3f0e43f8f SRPMS/pam-0.79-9.5.src.rpm 9f98b5b90303f371769d4b6de43db6c4 ppc/pam-0.79-9.5.ppc.rpm 73af727cbf25bf8716acaaa29ea7e330 ppc/pam-devel-0.79-9.5.ppc.rpm a04e8d8b11758402bd64dbc902043147 ppc/debug/pam-debuginfo-0.79-9.5.ppc.rpm 7548cfef970e82590da311e6f0b212bd ppc/pam-0.79-9.5.ppc64.rpm 46e011fdd61d7cad59a6b6e47190d19b ppc/pam-devel-0.79-9.5.ppc64.rpm c8624c43e9befba0c1b3630ca532b79c x86_64/pam-0.79-9.5.x86_64.rpm b39cee0df4b838fb4acc547afa41a2bc x86_64/pam-devel-0.79-9.5.x86_64.rpm a117147e767e2e0c88b4bfe85cab13f7 x86_64/debug/pam-debuginfo-0.79-9.5.x86_64.rpm 7817f4a44c13aa8e904edbd8f4fc2521 x86_64/pam-0.79-9.5.i386.rpm 5fbedd814834089317142b7900832a4a x86_64/pam-devel-0.79-9.5.i386.rpm 7817f4a44c13aa8e904edbd8f4fc2521 i386/pam-0.79-9.5.i386.rpm 5fbedd814834089317142b7900832a4a i386/pam-devel-0.79-9.5.i386.rpm 8021c28adcbdd132f17e07580b73c214 i386/debug/pam-debuginfo-0.79-9.5.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list
add argument to pam_console_apply to restrict its work to specified files. #140451 parse passwd entries correctly and test for failure. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-531 2004-12-20 ---------------------------------------------------------------------Product : Fedora Core 3 Name : pam Version : 0.77 Release : 66.1 Summary : A security tool which provides authentication for applications. Description : PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. ---------------------------------------------------------------------Update Information: This update resolves various minor bugs of pam package in Fedora Core 3 and adds a new parameter to pam_console_apply to constrain it's work to the specified files. ---------------------------------------------------------------------* Wed Dec 08 2004 Tomas Mraz 0.77-66.1 - add argument to pam_console_apply to restrict its work to specified files - #140451 parse passwd entries correctly and test for failure * Thu Nov 11 2004 Tomas Mraz 0.77-66 - #77646 log failures when renaming the files when changing password - Log failure on missing /etc/security/opasswd when remember option is present * Wed Nov 10 2004 Tomas Mraz - #87628 pam_timestamp remembers authorization after logout - #116956 fixed memory leaks in pam_stack ---------------------------------------------------------------------This update can be downloaded from: abb99f86fd1a9ed109b11f8004699dd8 SRPMS/pam-0.77-66.1.src.rpm b5246c33d3d12b5f82654efeee06fb55 x86_64/pam-0.77-66.1.x86_64.rpm aef0118ec92d301309025c7b68b4f4a0 x86_64/pam-devel-0.77-66.1.x86_64.rpm add741b0976f8b8057ecfe1404322767 x86_64/debug/pam-debuginfo-0.77-66.1.x86_64.rpm 394dee8ab21b39c055ca27b295b6dd6c x86_64/pam-0.77-66.1.i386.rpm 4bcffb03951f0fb215ebdfd34fcb7d7f x86_64/pam-devel-0.77-66.1.i386.rpm 394dee8ab21b39c055ca27b295b6dd6c i386/pam-0.77-66.1.i386.rpm 4bcffb03951f0fb215ebdfd34fcb7d7f i386/pam-devel-0.77-66.1.i386.rpm 2bfad85fcc36a808ce0883b17dafd623 i386/debug/pam-debuginfo-0.77-66.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.