]> code.ossystems Code Review - openembedded-core.git/commit
libpam: Fix for CVE-2010-4708
authorWenzong Fan <wenzong.fan@windriver.com>
Wed, 19 Jun 2013 03:21:29 +0000 (23:21 -0400)
committerPaul Eggleton <paul.eggleton@linux.intel.com>
Mon, 8 Jul 2013 09:30:19 +0000 (10:30 +0100)
commitb280268dd0976fe44a7227a99d8f5584c3b94ffa
treeb9ed934a4aaa1a30adf6a3a53ca30203dba9b2a5
parent995502d19cce43430c3f4dce80ce6ef5feee7421
libpam: Fix for CVE-2010-4708

Change default for user_readenv to 0 and document the
new default for user_readenv.

This fix from:
http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_env
/pam_env.c?r1=1.22&r2=1.23&view=patch
http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/modules/pam_env
/pam_env.8.xml?r1=1.7&r2=1.8&view=patch

(From OE-Core master rev: 871ae7a6453b3b66610fd8bbaa770c92be850e19)

Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-extended/pam/libpam/libpam-fix-for-CVE-2010-4708.patch [new file with mode: 0644]
meta/recipes-extended/pam/libpam_1.1.6.bb