~ubuntu-branches/ubuntu/natty/pam/natty-updates

« back to all changes in this revision

Viewing changes to debian/changelog

  • Committer: Bazaar Package Importer
  • Author(s): Marc Deslauriers
  • Date: 2011-10-18 10:03:44 UTC
  • Revision ID: james.westby@ubuntu.com-20111018100344-56ltdupljxh42cez
Tags: 1.1.2-2ubuntu8.4
* SECURITY UPDATE: possible code execution via incorrect environment file
  parsing (LP: #874469)
  - debian/patches-applied/CVE-2011-3148.patch: correctly count leading
    whitespace when parsing environment file in modules/pam_env/pam_env.c.
  - CVE-2011-3148
* SECURITY UPDATE: denial of service via overflowed environment variable
  expansion (LP: #874565)
  - debian/patches-applied/CVE-2011-3149.patch: when overflowing, exit
    with PAM_BUF_ERR in modules/pam_env/pam_env.c.
  - CVE-2011-3149
* SECURITY UPDATE: code execution via incorrect environment cleaning
  - debian/patches-applied/update-motd: updated to use clean environment
    and absolute paths in modules/pam_motd/pam_motd.c.
  - CVE-2011-XXXX

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
pam (1.1.2-2ubuntu8.4) natty-security; urgency=low
 
2
 
 
3
  * SECURITY UPDATE: possible code execution via incorrect environment file
 
4
    parsing (LP: #874469)
 
5
    - debian/patches-applied/CVE-2011-3148.patch: correctly count leading
 
6
      whitespace when parsing environment file in modules/pam_env/pam_env.c.
 
7
    - CVE-2011-3148
 
8
  * SECURITY UPDATE: denial of service via overflowed environment variable
 
9
    expansion (LP: #874565)
 
10
    - debian/patches-applied/CVE-2011-3149.patch: when overflowing, exit
 
11
      with PAM_BUF_ERR in modules/pam_env/pam_env.c.
 
12
    - CVE-2011-3149
 
13
  * SECURITY UPDATE: code execution via incorrect environment cleaning
 
14
    - debian/patches-applied/update-motd: updated to use clean environment
 
15
      and absolute paths in modules/pam_motd/pam_motd.c.
 
16
    - CVE-2011-XXXX
 
17
 
 
18
 -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 18 Oct 2011 10:03:44 -0400
 
19
 
1
20
pam (1.1.2-2ubuntu8.3) natty-security; urgency=low
2
21
 
3
22
  * SECURITY REGRESSION: