]> code.ossystems Code Review - openembedded-core.git/commit
libpam: Fix for CVE-2010-4708
authorWenzong Fan <wenzong.fan@windriver.com>
Wed, 19 Jun 2013 03:21:29 +0000 (23:21 -0400)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 19 Jun 2013 08:08:50 +0000 (09:08 +0100)
commit871ae7a6453b3b66610fd8bbaa770c92be850e19
tree96efe94f9b8bf9b6f5d8de16d5240db6dd4688cf
parentf24aed8d7e41cce277c6eff4ff5ab07b8e39ffff
libpam: Fix for CVE-2010-4708

Change default for user_readenv to 0 and document the
new default for user_readenv.

This fix from:
http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_env
/pam_env.c?r1=1.22&r2=1.23&view=patch
http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_env
/pam_env.8.xml?r1=1.7&r2=1.8&view=patch

Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-extended/pam/libpam/libpam-fix-for-CVE-2010-4708.patch [new file with mode: 0644]
meta/recipes-extended/pam/libpam_1.1.6.bb