Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 31 Mar 2014 14:32:09 +0400
From: "Dmitry V. Levin" <ldv@...linux.org>
To: oss-security@...ts.openwall.com
Subject: Re: pam_timestamp internals

Hi,

On Mon, Mar 24, 2014 at 01:46:43PM +0100, Sebastian Krahmer wrote:
> When playing with some PAM modules for my own projects, I came
> across some implications of pam_timestamp (which is part of
> upstream linux-pam) that should probably be addressed.
> 
> Most importantly, there seems to be a path traversal issue:

Thanks, Sebastian!  The issue has been fixed in upstream linux-pam by commit
https://git.fedorahosted.org/cgit/linux-pam.git/commit/?id=Linux-PAM-1_1_8-32-g9dcead8


-- 
ldv

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.