libpam-smb is a PAM authentication module which makes it possible to
authenticate users against a password database managed by Samba or a
Microsoft Windows server. If a long password is supplied, this can cause a
buffer overflow which could be exploited to execute arbitrary code with the
privileges of the process which invokes PAM services. See this advisory for more information.
Posted Sep 5, 2003 17:15 UTC (Fri) by ranger (guest, #6415)
[Link]
Mandrake ships pam_smb in the contribs (which is unsupported), for use in the case where the officially supported solution for authentication against Windows systems (winbind) is not suitable (ie against samba<3.0.0), thus official updates will not be made.
However, the maintainer of the package has made updated packages for Mandrake 9.1 available on the MandrakeClub mirrors (unsupported/MandrakeClub/9.1/i586 on any Mandrake-devel mirror).