SciLinux: CVE-2004-0813 pam SL3,x i386/x86_64
Summary
Date: Fri, 15 Jun 2007 17:31:25 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for pam on SL3,x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Moderate: pam security and bug fix updateIssue date: 2007-06-11CVE Names: CVE-2004-0813 CVE-2007-1716A flaw was found in the way the Linux kernel handled certain SG_IOcommands. Console users with access to certain device files had the abilityto damage recordable CD drives. The way pam_console handled permissions ofthese files has been modified to disallow access. This change also requiredmodifications to the cdrecord application. (CVE-2004-0813)A flaw was found in the way pam_console set console device permissions. Itwas possible for various console devices to retain ownership of the consoleuser after logging out, possibly leaking information to an unauthorizeduser. (CVE-2007-1716)The pam_unix module provides authentication against standard /etc/passwdand /etc/shadow files. The pam_stack module provides support for stackingPAM configuration files. Both of these modules contained small memory leakswhich caused problems in applications calling PAM authentication repeatedlyin the same process.SL 3.0.x SRPMS:cdrtools-2.01.0.a32-0.EL3.6.src.rpmpam-0.75-72.src.rpm i386:cdrecord-2.01.0.a32-0.EL3.6.i386.rpmcdrecord-devel-2.01.0.a32-0.EL3.6.i386.rpmmkisofs-2.01.0.a32-0.EL3.6.i386.rpmpam-0.75-72.i386.rpmpam-devel-0.75-72.i386.rpm x86_64:cdrecord-2.01.0.a32-0.EL3.6.x86_64.rpmcdrecord-devel-2.01.0.a32-0.EL3.6.x86_64.rpmmkisofs-2.01.0.a32-0.EL3.6.x86_64.rpmpam-0.75-72.i386.rpmpam-0.75-72.x86_64.rpmpam-devel-0.75-72.i386.rpmpam-devel-0.75-72.x86_64.rpm-Connie Sieh-Troy Dawson