Bug Fix Advisory Updated pam and usermode packages available

Advisory: RHBA-2001:149-14
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2001-11-02
Last updated on: 2001-11-14
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
OVAL: N/A

Details

Updated pam and usermode packages are now available for Red Hat Linux 7,
7.1, and 7.2. These updates fix a bug which would prevent X authorization
records from being correctly propagated to programs run using the
userhelper setuid helper program.

After setting the XAUTHORITY environment variable, the pam_xauth module
would incorrectly free the space used to hold the variable's value,
allowing it to be unintentionally modified when the space was later reused
in the calling program. The userhelper binary did not properly pass
environment variables set by PAM modules on to programs it ran.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains
the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.1

SRPMS:
pam-0.75-18.7.src.rpm
File outdated by:  RHSA-2003:035
    ee81f1aa49afa80104711f96e4120c23
ftp://updates.redhat.com/7.1/en/os/SRPMS/usermode-1.46-1.src.rpm
Missing file
    327f41fdb36e2113870422b04f7d28d5
 
Alpha:
ftp://updates.redhat.com/7.1/en/os/alpha/pam-0.75-18.7.alpha.rpm
Missing file
    a1c394c7aaa325e4b234980eaeb6d241
ftp://updates.redhat.com/7.1/en/os/alpha/pam-devel-0.75-18.7.alpha.rpm
Missing file
    6ed8fd14d0f7f66f9c812832f855d770
ftp://updates.redhat.com/7.1/en/os/alpha/usermode-1.46-1.alpha.rpm
Missing file
    74a5bdb1b7009e4eecfcdd77f021b8f2
 
IA-32:
pam-0.75-18.7.i386.rpm
File outdated by:  RHSA-2003:035
    c129be76b034e4fe6ef41e8756d03fc5
pam-devel-0.75-18.7.i386.rpm
File outdated by:  RHSA-2003:035
    c639bd9b0a211bede2aaffe6511f48b4
ftp://updates.redhat.com/7.1/en/os/i386/usermode-1.46-1.i386.rpm
Missing file
    f4f7ed9f4f4e45332ff3d7771e0c6c1c
 
IA-64:
ftp://updates.redhat.com/7.1/en/os/ia64/pam-0.75-18.7.ia64.rpm
Missing file
    239110cdbdd83755a148a02bd0e4eb7e
ftp://updates.redhat.com/7.1/en/os/ia64/pam-devel-0.75-18.7.ia64.rpm
Missing file
    239751f5e05aeefc05b8b51b968abf5a
ftp://updates.redhat.com/7.1/en/os/ia64/usermode-1.46-1.ia64.rpm
Missing file
    89105fecaf629c8065cef8fa0fdbdb22
 
Red Hat Linux 7.2

SRPMS:
pam-0.75-19.src.rpm
File outdated by:  RHSA-2003:035
    6b001534fa05e992e628d55701036aed
ftp://updates.redhat.com/7.2/en/os/SRPMS/usermode-1.46-1.src.rpm
Missing file
    327f41fdb36e2113870422b04f7d28d5
 
IA-32:
pam-0.75-19.i386.rpm
File outdated by:  RHSA-2003:035
    cd95d63d4f555cc04ee8e4146bc739e0
pam-devel-0.75-19.i386.rpm
File outdated by:  RHSA-2003:035
    1a524054cc979b4d056114c9dd958385
ftp://updates.redhat.com/7.2/en/os/i386/usermode-1.46-1.i386.rpm
Missing file
    f4f7ed9f4f4e45332ff3d7771e0c6c1c
 

Bugs fixed (see bugzilla for more information)

15528 - console.perms doesnt include any usb stuff
16505 - horrible italian description
36864 - pam_access not compiled with NIS netgroup support
39247 - pam_securetty barfs if PAM_TTY not set
43706 - pam_unix does not preserve file permissions
49613 - Password validation on forced password change
52321 - pam-devel doesn't contain libpam.a
55651 - Broken link in pam-devel update


Keywords

pam, xauthority


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/