|
Mandriva- Advisories MDKSA-2007:111: Updated util-linux packages address login access policies bypassing issue
Advisories MDKSA-2007:111: Updated util-linux packages address login access policies bypassing issue
login in util-linux-2.12a (and later versions) skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok. Updated packages have been patched to address this issue.
http://mandrivausers.org/index.php?showtopic=41937
Array
Mon, 04 Jun 2007 22:58:32 +0000
|