--------------------------------------------------------------------- Fedora Update Notification FEDORA-2005-1031 2005-10-27 --------------------------------------------------------------------- Product : Fedora Core 4 Name : pam Version : 0.79 Release : 9.6 Summary : A security tool which provides authentication for applications. Description : PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. --------------------------------------------------------------------- Update Information: This update fixes a security bug in unix_chkpwd allowing brute force attacks against passwords in /etc/shadow by a regular user when SELinux is enabled. --------------------------------------------------------------------- * Wed Oct 26 2005 Tomas Mraz <tmraz@xxxxxxxxxx> 0.79-9.6 - fixed CAN-2005-2977 unix_chkpwd should skip user verification only if run as root (#168181) - link pam_loginuid to libaudit - remove spurious glib2 dependency - support no tty in pam_access (#170467) - support new kernel limits and unlimited limit value in pam_limits (#171546) --------------------------------------------------------------------- This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/ fb348c5be5d8f694cdbd927681150989 SRPMS/pam-0.79-9.6.src.rpm 4a06122544169a7549639fa52be91bcd ppc/pam-0.79-9.6.ppc.rpm edf3fc81ac4dfddf44f25dd37142b23c ppc/pam-devel-0.79-9.6.ppc.rpm 873dca1bc06450ede87a40b9d0241398 ppc/debug/pam-debuginfo-0.79-9.6.ppc.rpm 054d2fe06507a3c45c7ef8bcf8a595ac ppc/pam-0.79-9.6.ppc64.rpm c7a3db12973f5182739d6adae0b25555 ppc/pam-devel-0.79-9.6.ppc64.rpm 6774937168a148b9e63e54711c26c790 x86_64/pam-0.79-9.6.x86_64.rpm 649b875ec7894c2fd855abb9a6547ef0 x86_64/pam-devel-0.79-9.6.x86_64.rpm a70f55b7f8ce114052362e167984fdb0 x86_64/debug/pam-debuginfo-0.79-9.6.x86_64.rpm 6674a4ea75709a1e5c7f905e617db12b x86_64/pam-0.79-9.6.i386.rpm f535f175a757f0d7b1dc66b1538fcd1c x86_64/pam-devel-0.79-9.6.i386.rpm 6674a4ea75709a1e5c7f905e617db12b i386/pam-0.79-9.6.i386.rpm f535f175a757f0d7b1dc66b1538fcd1c i386/pam-devel-0.79-9.6.i386.rpm d4ec56ab2def5974a103495169442c4c i386/debug/pam-debuginfo-0.79-9.6.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- -- fedora-announce-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-announce-list