diff options
author | Colin Watson <cjwatson@debian.org> | 2015-08-19 18:34:29 +0100 |
---|---|---|
committer | Colin Watson <cjwatson@debian.org> | 2015-08-19 18:37:32 +0100 |
commit | d2d9171e73cd2db10fabf9dd4924d3dcd5f13c7a (patch) | |
tree | deedfca8dcc980d858d5caacbde773e44a081bc2 /debian/patches/series | |
parent | a608a63196dbda54e9bdd656baa253c56e76bace (diff) | |
parent | c0ec3def4bec4afe1cad9e99081e658200b13a02 (diff) |
Backport PAM security fixes.
- sshd(8): Fixed a privilege separation weakness related to PAM support.
Attackers who could successfully compromise the pre-authentication
process for remote code execution and who had valid credentials on the
host could impersonate other users. Reported by Moritz Jodeit.
- sshd(8): Fixed a use-after-free bug related to PAM support that was
reachable by attackers who could compromise the pre-authentication
process for remote code execution (closes: #795711). Also reported by
Moritz Jodeit.
Diffstat (limited to 'debian/patches/series')
-rw-r--r-- | debian/patches/series | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/debian/patches/series b/debian/patches/series index bee70bc30..1a843eac8 100644 --- a/debian/patches/series +++ b/debian/patches/series | |||
@@ -28,3 +28,5 @@ gnome-ssh-askpass2-icon.patch | |||
28 | sigstop.patch | 28 | sigstop.patch |
29 | debian-config.patch | 29 | debian-config.patch |
30 | backport-fix-pty-permissions.patch | 30 | backport-fix-pty-permissions.patch |
31 | backport-do-not-resend-username-to-pam.patch | ||
32 | backport-pam-use-after-free.patch | ||