OpenSSH: multiple vulnerabilities in the new PAM code

Michael Sierchio kudzu at tenebras.com
Wed Sep 24 07:38:40 PDT 2003


Jacques A. Vidrine wrote:

> Unfortunately, it _does_ affect us.  The PAM code in OpenSSH 3.7x was
> taken from FreeBSD's PAM code.  des@ is working the issue now.

Jacques, Dag-Erling -

The effort is much appreciated.  There are a couple of PAMs I'm
working on at the moment, and would love to be able to trust
the AAA chain.

Regards,

MS



More information about the freebsd-security mailing list