oss-sec mailing list archives
Re: CVE Request: pam
From: Josh Bressers <bressers () redhat com>
Date: Tue, 18 Oct 2011 16:24:32 -0400 (EDT)
----- Original Message -----
Hello, Could a CVE please be assigned to the following issue: A Debian/Ubuntu specific patch in pam, update-motd, calls the scripts in /etc/update-motd.d as root without sanitizing the environment. See: https://bugs.launchpad.net/ubuntu/+source/pam/+bug/610125
Please use CVE-2011-3628.
Thanks.
--
JB
Current thread:
- CVE Request: pam Marc Deslauriers (Oct 18)
- Re: CVE Request: pam Josh Bressers (Oct 18)
- CVE Request: FreeBSD kernel Aurelien Jarno (Oct 19)
- Re: CVE Request: FreeBSD kernel Josh Bressers (Oct 20)
- Re: CVE Request: FreeBSD kernel Moritz Muehlenhoff (Oct 20)
- Re: CVE Request: FreeBSD kernel Eitan Adler (Oct 24)
- Re: CVE Request: FreeBSD kernel Colin Percival (Oct 24)
- Re: CVE Request: FreeBSD kernel Josh Bressers (Oct 20)
