Security Advisory New util-linux packages available to fix /bin/login pam problem

Advisory: RHSA-2001:132-04
Type: Security Advisory
Severity: N/A
Issued on: 2001-10-11
Last updated on: 2001-10-16
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2001-1147
CVE-2001-1175

Details

New util-linux packages are available that fix a problem with /bin/login's
PAM implementation. This could, in some non-default setups, cause users to
receive credentials of other users. It is recommended that all users
update to the fixed packages.

2001-10-22: Packages are now available for Red Hat Linux 7.2. Notably,
these packages also fix the problem noted in RHSA-2001:095-04 (vipw
incorrectly setting permissions on some files) - this bug was accidentally
reintroduced in Red Hat Linux 7.2.

A problem existed in /bin/login's PAM implementation; it stored the value
of a static pwent buffer across PAM calls; when used with some PAM modules
in non-default configuration (such as pam_limits), it would overwrite the
buffer, causing a user to get credentials of another user.

Thanks go to Tarhon-Onu Victor <mituc@ac.tuiasi.ro> for bringing the
problem to our attention, and to Olaf Kirch <okir@caldera.de> for providing
the patch.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains
the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.1

SRPMS:
util-linux-2.11f-11.7.1.src.rpm
File outdated by:  RHSA-2002:132
    db33b22f50978471a25fd5cc973f8f54
 
Alpha:
util-linux-2.11f-11.7.1.alpha.rpm
File outdated by:  RHSA-2002:132
    d55f6ec42e3c0268f2ab4decb24deb53
 
IA-32:
util-linux-2.11f-11.7.1.i386.rpm
File outdated by:  RHSA-2002:132
    2bf1db1cadc50f783220f70aa2b7a09c
 
IA-64:
util-linux-2.11f-11.7.1.ia64.rpm
File outdated by:  RHSA-2002:132
    568c4ec61cb9cc0ebd6313fb14d0419c
 
Red Hat Linux 7.2

SRPMS:
util-linux-2.11f-12.src.rpm
File outdated by:  RHSA-2002:132
    3b5448a60fa6cb5580eb690a303827a5
 
IA-32:
util-linux-2.11f-12.i386.rpm
File outdated by:  RHSA-2002:132
    c0f329c070e416fbb20c97670199d3fe
 

Bugs fixed (see bugzilla for more information)

51646 - pam limits drops other user privileges


References


Keywords

login, pam, pam_limits


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/