effectivement, ils ont également prévenu la liste bugtrack que le package util-linux qui avait été relivré en 7.1 doit aussi etre réinstallé car celui de la 7.2 possède le trou de sécurité :
New util-linux packages are available that fix a problem with /bin/login's
PAM implementation. This could, in some non-default setups, cause users to
receive credentials of other users. It is recommended that all users
update to the fixed packages.
2001年10月22日: Packages are now available for Red Hat Linux 7.2. Notably,
these packages also fix the problem noted in RHSA-2001:095-04 (vipw
incorrectly setting permissions on some files) - this bug was accidentally
reintroduced in Red Hat Linux 7.2.
[^] # Re: Noyau 2.4.7 ?
Posté par PLuG . En réponse à la dépêche Red Hat 7.2 dispo. Évalué à -1.
New util-linux packages are available that fix a problem with /bin/login's
PAM implementation. This could, in some non-default setups, cause users to
receive credentials of other users. It is recommended that all users
update to the fixed packages.
2001年10月22日: Packages are now available for Red Hat Linux 7.2. Notably,
these packages also fix the problem noted in RHSA-2001:095-04 (vipw
incorrectly setting permissions on some files) - this bug was accidentally
reintroduced in Red Hat Linux 7.2.