Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in PyPAM
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in PyPAM
ID: USN-1395-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04, Ubuntu 11.10
Datum: Do, 8. März 2012, 22:32
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1502
Applikationen: PyPAM

Originalnachricht


--===============0436215894588050980==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-+efNGiyz6LGA0aga5GqM"


--=-+efNGiyz6LGA0aga5GqM
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1395-1
March 08, 2012

python-pam vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

PyPAM could be made to crash or possibly run programs if it processed
a specially crafted password.

Software Description:
- python-pam: A Python interface to the PAM library

Details:

Markus Vervier discovered that PyPAM incorrectly handled passwords
containing NULL bytes. An attacker could exploit this to cause applications
using PyPAM to crash, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
python-pam 0.4.2-12.2ubuntu2.11.10.1

Ubuntu 11.04:
python-pam 0.4.2-12.2ubuntu2.11.04.1

Ubuntu 10.10:
python-pam 0.4.2-12.1ubuntu1.10.10.1

Ubuntu 10.04 LTS:
python-pam 0.4.2-12.1ubuntu1.10.04.1

After a standard system update you need to restart applications that use
PyPAM to make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1395-1
CVE-2012-1502

Package Information:
https://launchpad.net/ubuntu/+source/python-pam/0.4.2-12.2ubuntu2.11.10.1
https://launchpad.net/ubuntu/+source/python-pam/0.4.2-12.2ubuntu2.11.04.1
https://launchpad.net/ubuntu/+source/python-pam/0.4.2-12.1ubuntu1.10.10.1
https://launchpad.net/ubuntu/+source/python-pam/0.4.2-12.1ubuntu1.10.04.1



--ÛefNGiyz6LGA0aga5GqM
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPWPuIAAoJEGVp2FWnRL6TulIP/iss7P+fTCeeF+S11AMoRSy3
WHrXaPRgrTIt7jDK8SlZzvrKsS7C2XwVJNijGqt2syBhYjC89vTMjChFBs8WOPEt
lThAOP2z2pNN6TlBwEdWIzU6Km3m7wU22dJjTHZr8JRod+ptMj5IihDho+SPzNeN
JtacwuuDvgQEROK/L7E6qz6A+41qvGZbOCHMQLjeERzvnenxnUMVzbV/7AH4jo5X
gr/7KZTzCFl/OP+N4KkrMDoVfFmfKQv5/rI8yFRUL1z+gDEb6j95OWkPdqP4qonH
BJGS/53w7TkQlK4hU8Dzl+sv2RQOv3P5l5LHRg/0JXjFlJ0q0Pl2IYbDZblOxQKL
fNaLqdzWM9WiJkMV6B1FoOWkhNfv5uIOA4VxrPq67CyfEGYEOOOrDaFOh27s6p4j
cQND1w1fRtZ2ME+WuZw4rSh/GkFxd8Ue9iALlRSA3Sblb29nTzcpvFGY4Pk0Hxlu
6u72mdBRZGMu/AFrJ1OaxWqu8eoVGtXsvuRPxF2U0m+zLRAY5PLHP2VlGJA4BYo9
zwvv/rGo9bFMJQhdKFdM+I9Eu92cKWjwJPTNZu0d7kuY0+7/q5L/r2xTjEIuqsNR
Q3R60sv8mC3tt921ayhVkKSjWFOTu4DHUz0n01lc1QkOeMojHC03ZQzEPQhnD4CT
xzHFzcszURiLuN3f2YBj
=O+Ak
-----END PGP SIGNATURE-----

--=-+efNGiyz6LGA0aga5GqM--



--===============0436215894588050980==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============0436215894588050980==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung