Updated PAM packages are now available for Red Hat Linux 7.1, 7.2, 7.3, and
8.0. These packages correct a bug in pam_xauth's handling of authorization
data for the root user.
[Updated 16 April 2003]
Added packages for Red Hat Linux on IBM iSeries and pSeries systems.
The pam_xauth module is used to forward xauth information from user to user
in applications such as 'su'.
Andreas Beck discovered that versions of pam_xauth supplied with Red Hat
Linux since version 7.1 would forward authorization information from the
root account to unprivileged users. This could be used by a local attacker
to gain access to an administrator's X session. In order to exploit this
vulnerability, the attacker would have to get the administrator, as root,
to use su to the account belonging to the attacker.
Users of pam_xauth are advised to upgrade to these errata packages, which
contain a patch that adds ACL (access control list) functionality to
pam_xauth and disallows root forwarding by default.
Versions of pam_xauth included in Red Hat Linux 7 and earlier disabled
passing of credentials from the root account to unprivileged users by
default and are not affected by this issue.
Thanks to Andreas Beck for reporting this issue.
| Red Hat Linux 7.1 |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/SRPMS/pam-0.75-46.7.1.src.rpm
Missing file |
4a869dd0efd82fb9f098cc4284263aeb |
| |
| IA-32: |
ftp://updates.redhat.com/7.1/en/os/i386/pam-0.75-46.7.1.i386.rpm
Missing file |
2ee6c4e7c9c59efdf3e31c8d9482a30a |
ftp://updates.redhat.com/7.1/en/os/i386/pam-devel-0.75-46.7.1.i386.rpm
Missing file |
0d8f6cb6d0f293cb174f3e376c21eb1d |
| |
| Red Hat Linux 7.1 for iSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/iSeries/SRPMS/pam-0.75-46.7.1.src.rpm
Missing file |
4a869dd0efd82fb9f098cc4284263aeb |
| |
| iSeries: |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/pam-0.75-46.7.1.ppc.rpm
Missing file |
487929049588a3f38d16e5eca3e53f32 |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/pam-devel-0.75-46.7.1.ppc.rpm
Missing file |
4ec530ffeac21f9a7c9e2dddc271feed |
| |
| Red Hat Linux 7.1 for pSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/pSeries/SRPMS/pam-0.75-46.7.1.src.rpm
Missing file |
4a869dd0efd82fb9f098cc4284263aeb |
| |
| pSeries: |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/pam-0.75-46.7.1.ppc.rpm
Missing file |
487929049588a3f38d16e5eca3e53f32 |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/pam-devel-0.75-46.7.1.ppc.rpm
Missing file |
4ec530ffeac21f9a7c9e2dddc271feed |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
ftp://updates.redhat.com/7.2/en/os/SRPMS/pam-0.75-46.7.2.src.rpm
Missing file |
fcbe7194fc12466d4532b213373c3ce6 |
| |
| IA-32: |
ftp://updates.redhat.com/7.2/en/os/i386/pam-0.75-46.7.2.i386.rpm
Missing file |
7d16c011e4f74e8e02bb8c193506186d |
ftp://updates.redhat.com/7.2/en/os/i386/pam-devel-0.75-46.7.2.i386.rpm
Missing file |
0919b62d8d7531883d6e01f5ff3a51b6 |
| |
| IA-64: |
ftp://updates.redhat.com/7.2/en/os/ia64/pam-0.75-46.7.2.ia64.rpm
Missing file |
e653e3ff25eb958570b411d201b5106e |
ftp://updates.redhat.com/7.2/en/os/ia64/pam-devel-0.75-46.7.2.ia64.rpm
Missing file |
8f4d0dc64cdbded20c46a38460e6affe |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
ftp://updates.redhat.com/7.3/en/os/SRPMS/pam-0.75-46.7.3.src.rpm
Missing file |
99751631043fbe42f98f8598e74e6d4b |
| |
| IA-32: |
ftp://updates.redhat.com/7.3/en/os/i386/pam-0.75-46.7.3.i386.rpm
Missing file |
8ea6d868c28c22d629d2059f1ad72f1b |
ftp://updates.redhat.com/7.3/en/os/i386/pam-devel-0.75-46.7.3.i386.rpm
Missing file |
9fef754632838504c0590ba30203a925 |
| |
| Red Hat Linux 8.0 |
|
| SRPMS: |
ftp://updates.redhat.com/8.0/en/os/SRPMS/pam-0.75-46.8.0.src.rpm
Missing file |
1b74821ca4fd0b7a9919c3b0fdf3dbb3 |
| |
| IA-32: |
ftp://updates.redhat.com/8.0/en/os/i386/pam-0.75-46.8.0.i386.rpm
Missing file |
25ebcb39f56c98cc064c34b2d048ed35 |
ftp://updates.redhat.com/8.0/en/os/i386/pam-devel-0.75-46.8.0.i386.rpm
Missing file |
f6412156d54a4021a3200eb7d7ff79c0 |
| |