User: Password:
Subscribe / Log in / New account

SUSE alert SUSE-SU-2011:1209-1 (pam)

Subject:  [security-announce] SUSE-SU-2011:1209-1: important: Security update for pam
Date:  Thu, 3 Nov 2011 00:08:45 +0100 (CET)
Message-ID:  <>
Archive-link:  Article, Thread

SUSE Security Update: Security update for pam ______________________________________________________________________________ Announcement ID: SUSE-SU-2011:1209-1 Rating: important References: #568833 #631802 #703187 #724480 Cross-References: CVE-2010-3316 CVE-2011-3148 CVE-2011-3149 Affected Products: SUSE Linux Enterprise Server 10 SP3 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: The pam_env module is vulnerable to a stack overflow (CVE-2011-3148) and a DoS condition (CVE-2011-3149) when parsing users .pam_environment files. Additionally a missing return value check inside pam_xauth has been fixed (CVE-2010-3316). Security Issue references: * CVE-2011-3148 < > * CVE-2011-3149 < > * CVE-2010-3316 < > Package List: - SUSE Linux Enterprise Server 10 SP3 (i586 ia64 ppc s390x x86_64): pam- pam-devel- - SUSE Linux Enterprise Server 10 SP3 (s390x x86_64): pam-32bit- pam-devel-32bit- - SUSE Linux Enterprise Server 10 SP3 (ia64): pam-x86- - SUSE Linux Enterprise Server 10 SP3 (ppc): pam-64bit- pam-devel-64bit- References: -- To unsubscribe, e-mail: For additional commands, e-mail:

(Log in to post comments)

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds