Skip to navigation

Bug Fix Advisory pam bug fix update

Advisory: RHBA-2010:0135-1
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2010-03-11
Last updated on: 2010-03-11
Affected Products: RHEL Desktop Workstation (v. 5 client)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux EUS (v. 5.4.z server)

Details

Updated pam packages that fix a bug in the pam_time and pam_group modules
are
now available.

Pluggable Authentication Modules (PAM) provide a system whereby
administrators can set up authentication policies, without having to
recompile programs to handle authentication.

These updated packages fix the following bug:

* the pam_time and pam_group modules, which support allowing or rejecting
authentication based on time and assigning group names respectively,
incorrectly matched user, service, or terminal name substrings even if no
wildcard was specified in the configuration. For example, "user" and
"user1" were incorrectly equated, causing policies to apply to both
usernames even when "user" was the only username subject to said policies.
This update improves the string matching in the pam_time and pam_group
modules ensuring such mis-matches (and consequent policy mis-applications)
no longer occur. (BZ#571341)

All pam users are advised to upgrade to these updated packages, which
resolve this issue.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

Updated packages

RHEL Desktop Workstation (v. 5 client)

SRPMS:
pam-0.99.6.2-6.el5_4.1.src.rpm
File outdated by:  RHSA-2010:0819
    MD5: c17968252fff302515f080089303f465
 
IA-32:
pam-devel-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: f69a4b3cb2e91f9ae6f1800f5324893d
 
x86_64:
pam-devel-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: f69a4b3cb2e91f9ae6f1800f5324893d
pam-devel-0.99.6.2-6.el5_4.1.x86_64.rpm
File outdated by:  RHSA-2010:0819
    MD5: ae319d1bc22f3da3ccd4806fbac49a41
 
Red Hat Enterprise Linux (v. 5 server)

SRPMS:
pam-0.99.6.2-6.el5_4.1.src.rpm
File outdated by:  RHSA-2010:0819
    MD5: c17968252fff302515f080089303f465
 
IA-32:
pam-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: 729353557dc1e67ca9e42668e03d5469
pam-devel-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: f69a4b3cb2e91f9ae6f1800f5324893d
 
IA-64:
pam-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: 729353557dc1e67ca9e42668e03d5469
pam-0.99.6.2-6.el5_4.1.ia64.rpm
File outdated by:  RHSA-2010:0819
    MD5: c118a3b6c9bf52c1c72d4113f15759d7
pam-devel-0.99.6.2-6.el5_4.1.ia64.rpm
File outdated by:  RHSA-2010:0819
    MD5: 134ffeaf917896e70c6c94a65f6bca55
 
PPC:
pam-0.99.6.2-6.el5_4.1.ppc.rpm
File outdated by:  RHSA-2010:0819
    MD5: 92a77574bdeac106b2397211b05ef290
pam-0.99.6.2-6.el5_4.1.ppc64.rpm
File outdated by:  RHSA-2010:0819
    MD5: 38bd9b6999bf5d02c52ad6e41a1c79bd
pam-devel-0.99.6.2-6.el5_4.1.ppc.rpm
File outdated by:  RHSA-2010:0819
    MD5: 671e3d9aa9af5b6a5c1e3f9c0a368b2d
pam-devel-0.99.6.2-6.el5_4.1.ppc64.rpm
File outdated by:  RHSA-2010:0819
    MD5: 697e37137eae8bc63318dece768517b5
 
s390x:
pam-0.99.6.2-6.el5_4.1.s390.rpm
File outdated by:  RHSA-2010:0819
    MD5: ab4c3dc18768cbebe1cbe74c459e6bdf
pam-0.99.6.2-6.el5_4.1.s390x.rpm
File outdated by:  RHSA-2010:0819
    MD5: df6c343023bc5f5377f163ee869d82c2
pam-devel-0.99.6.2-6.el5_4.1.s390.rpm
File outdated by:  RHSA-2010:0819
    MD5: d50ff9d7525ce866a72527a5f961e241
pam-devel-0.99.6.2-6.el5_4.1.s390x.rpm
File outdated by:  RHSA-2010:0819
    MD5: b852114b22b333d33b70aa3654720c4e
 
x86_64:
pam-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: 729353557dc1e67ca9e42668e03d5469
pam-0.99.6.2-6.el5_4.1.x86_64.rpm
File outdated by:  RHSA-2010:0819
    MD5: 92a262703c6f5bc1d63b8839691a4a04
pam-devel-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: f69a4b3cb2e91f9ae6f1800f5324893d
pam-devel-0.99.6.2-6.el5_4.1.x86_64.rpm
File outdated by:  RHSA-2010:0819
    MD5: ae319d1bc22f3da3ccd4806fbac49a41
 
Red Hat Enterprise Linux Desktop (v. 5 client)

SRPMS:
pam-0.99.6.2-6.el5_4.1.src.rpm
File outdated by:  RHSA-2010:0819
    MD5: c17968252fff302515f080089303f465
 
IA-32:
pam-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: 729353557dc1e67ca9e42668e03d5469
 
x86_64:
pam-0.99.6.2-6.el5_4.1.i386.rpm
File outdated by:  RHSA-2010:0819
    MD5: 729353557dc1e67ca9e42668e03d5469
pam-0.99.6.2-6.el5_4.1.x86_64.rpm
File outdated by:  RHSA-2010:0819
    MD5: 92a262703c6f5bc1d63b8839691a4a04
 
Red Hat Enterprise Linux EUS (v. 5.4.z server)

SRPMS:
pam-0.99.6.2-6.el5_4.1.src.rpm
File outdated by:  RHSA-2010:0819
    MD5: c17968252fff302515f080089303f465
 
IA-32:
pam-0.99.6.2-6.el5_4.1.i386.rpm     MD5: 729353557dc1e67ca9e42668e03d5469
pam-devel-0.99.6.2-6.el5_4.1.i386.rpm     MD5: f69a4b3cb2e91f9ae6f1800f5324893d
 
IA-64:
pam-0.99.6.2-6.el5_4.1.i386.rpm     MD5: 729353557dc1e67ca9e42668e03d5469
pam-0.99.6.2-6.el5_4.1.ia64.rpm     MD5: c118a3b6c9bf52c1c72d4113f15759d7
pam-devel-0.99.6.2-6.el5_4.1.ia64.rpm     MD5: 134ffeaf917896e70c6c94a65f6bca55
 
PPC:
pam-0.99.6.2-6.el5_4.1.ppc.rpm     MD5: 92a77574bdeac106b2397211b05ef290
pam-0.99.6.2-6.el5_4.1.ppc64.rpm     MD5: 38bd9b6999bf5d02c52ad6e41a1c79bd
pam-devel-0.99.6.2-6.el5_4.1.ppc.rpm     MD5: 671e3d9aa9af5b6a5c1e3f9c0a368b2d
pam-devel-0.99.6.2-6.el5_4.1.ppc64.rpm     MD5: 697e37137eae8bc63318dece768517b5
 
s390x:
pam-0.99.6.2-6.el5_4.1.s390.rpm     MD5: ab4c3dc18768cbebe1cbe74c459e6bdf
pam-0.99.6.2-6.el5_4.1.s390x.rpm     MD5: df6c343023bc5f5377f163ee869d82c2
pam-devel-0.99.6.2-6.el5_4.1.s390.rpm     MD5: d50ff9d7525ce866a72527a5f961e241
pam-devel-0.99.6.2-6.el5_4.1.s390x.rpm     MD5: b852114b22b333d33b70aa3654720c4e
 
x86_64:
pam-0.99.6.2-6.el5_4.1.i386.rpm     MD5: 729353557dc1e67ca9e42668e03d5469
pam-0.99.6.2-6.el5_4.1.x86_64.rpm     MD5: 92a262703c6f5bc1d63b8839691a4a04
pam-devel-0.99.6.2-6.el5_4.1.i386.rpm     MD5: f69a4b3cb2e91f9ae6f1800f5324893d
pam-devel-0.99.6.2-6.el5_4.1.x86_64.rpm     MD5: ae319d1bc22f3da3ccd4806fbac49a41
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

571341 - pam_time not handling usernames correctly



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/