Red Hat Bugzilla – Bug 104648
CAN-2003-0690 xdm pam_setcred vulnerability
Last modified: 2007-11-30 17:06:53 EST
xdm does not verify whether the pam_setcred
function call succeeds, which may allow attackers to gain root
privileges by triggering error conditions within PAM modules,
as demonstrated in certain configurations of the MIT pam_krb5
Update currently being tested
An errata has been issued which should help the problem described in this bug report.
This report is therefore being closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, please follow the link below. You may reopen
this bug report if the solution does not work for you.