Bug#608273: CVE-2010-3853: pam_namespace executes namespace.init with service's environment

2010-12-30 Thread Julien Cristau
user release.debian@packages.debian.org usertag 608273 squeeze-can-defer tag 608273 squeeze-ignore kthxbye On Wed, Dec 29, 2010 at 16:15:44 +0100, Giuseppe Iuculano wrote: Package: pam Severity: serious Tags: security patch Tomas Mraz pointed out that pam_namespace PAM module executes

Bug#608273: CVE-2010-3853: pam_namespace executes namespace.init with service's environment

2010-12-29 Thread Giuseppe Iuculano
Package: pam Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Tomas Mraz pointed out that pam_namespace PAM module executes external namespace.init script with an environment settings inherited form the program or service that has pam_namespace configured.