Name: | pam |
---|---|
Version: | 1.3.1 |
Release: | 36.0.1.el8_10 |
Architecture: | x86_64 |
Group: | System Environment/Base |
Size: | 2649704 |
License: | BSD and GPLv2+ |
RPM: | pam-1.3.1-36.0.1.el8_10.x86_64.rpm |
Source RPM: | pam-1.3.1-36.0.1.el8_10.src.rpm |
Build Date: | Tue Nov 26 2024 |
Build Host: | build-ol8-x86_64.oracle.com |
Vendor: | Oracle America |
URL: | http://www.linux-pam.org/ |
Summary: | An extensible library which provides authentication for applications |
Description: | PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. |
- pam_limits: fix use after free in pam_sm_open_session [Orabug: 36272695]
- pam_access: rework resolving of tokens as hostname. Resolves: CVE-2024-10963 and RHEL-66242
- pam_unix: always run the helper to obtain shadow password file entries. CVE-2024-10041. Resolves: RHEL-62877 - pam_access: always match local address and clarify LOCAL keyword behaviour. Resolves: RHEL-23018 - libpam: support long lines in service files. Resolves: RHEL-5051
- fix formatting of audit messages. Resolves: RHEL-28620
- pam_namespace: protect_dir(): use O_DIRECTORY to prevent local DoS situations. CVE-2024-22365. Resolves: RHEL-21242
- pam_access: handle hostnames in access.conf. Resolves: RHEL-3374
- pam_faillock: create tallydir before creating tallyfile. Resolves: RHEL-19810
- pam_unix: enable bcrypt. Resolves: RHEL-5057
- pam_misc: make length of misc_conv() configurable and set to 4096. Resolves: #2209785
- smartcard-auth: modify the content to remove unnecessary modules. Resolves: #1983683