LWN.net Logo

[Security Announce] [ MDKA-2006:045 ] - Updated coreutils package correctly links against PAM

From:  security-AT-mandriva.com
To:  security-announce-AT-mandrivalinux.org
Subject:  [Security Announce] [ MDKA-2006:045 ] - Updated coreutils package correctly links against PAM
Date:  Mon, 23 Oct 2006 14:00:01 -0600


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________
 
 Mandriva Linux Advisory                                   MDKA-2006:045
 http://www.mandriva.com/security/
 _______________________________________________________________________
 
 Package : coreutils
 Date    : October 23, 2006
 Affected: 2007.0
 _______________________________________________________________________
 
 Problem Description:
 
 The coreutils package lacked several features due to a build
 deficiency. As a result, the su program was not linked against the PAM
 library, making it impossible for su to make use of advanced
 authentication features that rely on the PAM library.  As well, the cp
 system utility did not keep extended attributes and ACLs in file
 copies.

 This has been corrected in the updated packages.
 _______________________________________________________________________

 References:
 
 http://qa.mandriva.com/show_bug.cgi?id=26353
 _______________________________________________________________________
 
 Updated Packages:
 
 Mandriva Linux 2007.0:
 a0b61362e040873a0a179aee3b85f213  2007.0/i586/coreutils-5.97-5.1mdv2007.0.i586.rpm
 f40391c88a1b2c64ea8d0a338916458a  2007.0/i586/coreutils-doc-5.97-5.1mdv2007.0.i586.rpm 
 259ee72877fc29ee8b92265aefbd917c  2007.0/SRPMS/coreutils-5.97-5.1mdv2007.0.src.rpm

 Mandriva Linux 2007.0/X86_64:
 eeefc9c4bafd2306ec328adbf7c637bf  2007.0/x86_64/coreutils-5.97-5.1mdv2007.0.x86_64.rpm
 c50bb3eb82516194fd9d5451637bedbe  2007.0/x86_64/coreutils-doc-5.97-5.1mdv2007.0.x86_64.rpm 
 259ee72877fc29ee8b92265aefbd917c  2007.0/SRPMS/coreutils-5.97-5.1mdv2007.0.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/security/advisories

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFFPPUImqjQ0CJFipgRAgy+AJ4urYLETHRCY+HNSxgTjTN7hg7UjACg6y88
579mALzzQshzJQpiNq+1Lo8=
=OWVj
-----END PGP SIGNATURE-----


To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________



(Log in to post comments)

Copyright © 2006, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds