Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 512498 (CVE-2014-3879) - <sys-auth/openpam-20140912: Incorrect error handling in PAM policy parser (CVE-2014-3879)
Summary: <sys-auth/openpam-20140912: Incorrect error handling in PAM policy parser (CV...
Status: RESOLVED FIXED
Alias: CVE-2014-3879
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All FreeBSD
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openpam.org/wiki/Errata?ve...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-05 11:23 UTC by Yuta SATOH
Modified: 2016-03-29 07:59 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Yuta SATOH 2014-06-05 11:23:52 UTC
Please add the patch, and revision bump.
Details, please see URL.


Patch URL:
openpam-20130907 (Nummularia)
http://www.openpam.org/changeset/795/openpam?format=diff&new=795
or
http://security.FreeBSD.org/patches/SA-14:13/pam-freebsd10.patch

openpam-20120526 (Micrampelis)
http://security.FreeBSD.org/patches/SA-14:13/pam-freebsd9.patch

See also:
http://www.freebsd.org/security/advisories/FreeBSD-SA-14:13.pam.asc


Reproducible: Always
Comment 1 Yuta SATOH 2014-09-17 11:02:41 UTC
New version is out. Please version bump.
http://www.openpam.org/wiki/Releases/Ourouparia

cd sys-auth/openpam
cp openpam-20130907.ebuild openpam-20140912.ebuild
ebuild openpam-20140912.ebuild digest
Comment 2 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2015-02-22 10:04:13 UTC
+*openpam-20140912 (22 Feb 2015)
+
+  22 Feb 2015; Michał Górny <mgorny@gentoo.org> +openpam-20140912.ebuild,
+  -openpam-20071221.ebuild, -openpam-20111218.ebuild,
+  -openpam-20120526-r1.ebuild, -openpam-20120526.ebuild,
+  -openpam-20130907.ebuild:
+  Version bump for security bug #512498. Remove old. https://github.com/gentoo
+  /gentoo-portage-rsync-mirror/pull/35 by nigoro.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2016-03-29 07:59:43 UTC
No vulnerable versions in tree.