From owner-freebsd-security@FreeBSD.ORG Thu May 27 13:33:27 2010 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 1EF501065673 for ; Thu, 27 May 2010 13:33:27 +0000 (UTC) (envelope-from delphij@gmail.com) Received: from mail-pz0-f183.google.com (mail-pz0-f183.google.com [209.85.222.183]) by mx1.freebsd.org (Postfix) with ESMTP id E29438FC1C for ; Thu, 27 May 2010 13:33:26 +0000 (UTC) Received: by pzk13 with SMTP id 13so5614883pzk.13 for ; Thu, 27 May 2010 06:33:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:received :in-reply-to:references:date:message-id:subject:from:to:cc :content-type; bh=m1PQjE6h6kchUtP7p2uIK2GtXFnIq3/XpXODuCA1Z38=; b=OYprIfo406utgkvDK3WWPZx/WG4oQ8/USt3Al0/AHAHC/rcpPjWYiNu1x4jCJD1VDB v7T44KIhL3oJ62XrFp5sY3df2KqMRRCMtJVzExdKzc7xwYA3ngcJlrIl0qTXEN4cOLDl Ux/BwjxNJNsmMUCqAvhjB/QXd6P1dzIMLUsqo= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=fHFwtX7QCdnUmQNwMOiCSDxZeVV7Rtsu2k2gHClzmRQK3b17ivcXndt+IqI/KeJ0wF TE5x1jjRCGU9y95ZnX3YRZZBbY4CiPjXwLXN3h4+d/hZP6KVenUm5pU0wZ2kzGwSZUv+ 2xYgYKSr/3jxckQEWhk6OH27J3xBhYdfqi6PM= MIME-Version: 1.0 Received: by 10.141.125.7 with SMTP id c7mr2230480rvn.228.1274965710687; Thu, 27 May 2010 06:08:30 -0700 (PDT) Received: by 10.140.140.8 with HTTP; Thu, 27 May 2010 06:08:30 -0700 (PDT) Received: by 10.140.140.8 with HTTP; Thu, 27 May 2010 06:08:30 -0700 (PDT) In-Reply-To: <86d3wh3aie.fsf@ds4.des.no> References: <201005270325.o4R3P7Bj009279@freefall.freebsd.org> <86d3wh3aie.fsf@ds4.des.no> Date: Thu, 27 May 2010 06:08:30 -0700 Message-ID: From: Xin LI To: =?UTF-8?Q?Dag=2DErling_Sm=C3=B8rgrav?= Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-security@freebsd.org, Dmitry Pryanishnikov Subject: Re: FreeBSD Security Advisory FreeBSD-SA-10:05.opie X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 27 May 2010 13:33:27 -0000 PAM opie implementation was careful enough not triggering this issue. So no, programs using solely PAM, configured or not configured with OPIE, are not affected. Programs that links directly to OPIE may be affected, depending on their usage. On May 27, 2010 3:30 AM, "Dag-Erling Sm=C3=B8rgrav" wrote: Dmitry Pryanishnikov writes: > Wouldn't just commenting out all references t... With my PAM maintainer hat on: yes. I'm surprised secteam didn't bother to ask me. DES -- Dag-Erling Sm=C3=B8rgrav - des@des.no _______________________________________________ freebsd-security@freebsd.org mailing list http://lis...