SUSE-SU-2016:1645-1
Dashboard / Vulnerabilities / SUSE-SU-2016:1645-1
SUSE-SU-2016:1645-1
Summary: Security update for pam
Details: This update for pam fixes two security issues. These security issues were fixed: - CVE-2015-3238: pam_unix in conjunction with SELinux allowed for DoS attacks (bsc#934920). - CVE-2013-7041: Compare password hashes case-sensitively (bsc#854480). This non-security issue was fixed: - bsc#962220: Don't fail when /var/log/btmp is corrupted
References: https://www.suse.com/support/update/announcement/2016/suse-su-20161645-1/, https://bugzilla.suse.com/854480, https://bugzilla.suse.com/934920, https://bugzilla.suse.com/962220, https://www.suse.com/security/cve/CVE-2013-7041, https://www.suse.com/security/cve/CVE-2015-3238
Affected packages
Package
Name: pam
Purl: pkg:rpm/suse/pam&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
