[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-security] PAM and CobaltOS 5.0



Hi,

> -----Original Message-----
> However, PAM is still ownable.  Cobalt missed it and didn't
> issue a patch
> by the looks of it (nothing on cobalt.com).  Since PAM itself is still
> vun, it's probably possible to exploit it (just not through
> userhelper).

On my RaQ3 a #> rpm -q pam gives me "pam-0.68-10C1". The L0pht Advisory
you mentioned refers to a Red Hat pam-0.68-10 as a patch... Maybe this
was among one of the numerous undeclared Cobalt patches?

Matthias
--

 w e b f a c t o r y   G m b H
   Matthias Pigulla <mp@xxxxxxxxxxxxx> - Geschaeftsfuehrer
   Lessingstr. 60 - D-53113 Bonn - Germany - www.webfactory.de
   Fon +49(0)228-9114455 - Fax +49(0)228-9114499 - ICQ 6394233