summaryrefslogtreecommitdiff
path: root/debian/patches-applied/cve-2011-4708.patch
blob: eb67e789c9243c989395761441c666748a6c5c61 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
Description: fix cve-2011-4708: .pam_environment privilege issue
Index: pam.debian/modules/pam_env/pam_env.c
===================================================================
--- pam.debian.orig/modules/pam_env/pam_env.c
+++ pam.debian/modules/pam_env/pam_env.c
@@ -10,7 +10,7 @@
 #define DEFAULT_READ_ENVFILE    1
 
 #define DEFAULT_USER_ENVFILE    ".pam_environment"
-#define DEFAULT_USER_READ_ENVFILE 1
+#define DEFAULT_USER_READ_ENVFILE 0
 
 #include "config.h"
 
Index: pam.debian/modules/pam_env/pam_env.8.xml
===================================================================
--- pam.debian.orig/modules/pam_env/pam_env.8.xml
+++ pam.debian/modules/pam_env/pam_env.8.xml
@@ -147,7 +147,7 @@
         <listitem>
           <para>
             Turns on or off the reading of the user specific environment
-            file. 0 is off, 1 is on. By default this option is on.
+            file. 0 is off, 1 is on. By default this option is off.
           </para>
         </listitem>
       </varlistentry>