[libpam4j] 02/02: Update changelog

Markus Koschany apo at moszumanska.debian.org
Tue Nov 7 13:08:16 UTC 2017


This is an automated email from the git hooks/post-receive script.

apo pushed a commit to branch master
in repository libpam4j.

commit d072577b9e1403950f7bdba2a2d8103b51874514
Author: Markus Koschany <apo at debian.org>
Date:   Tue Nov 7 13:42:21 2017 +0100

    Update changelog
---
 debian/changelog | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/debian/changelog b/debian/changelog
index 8500a5c..6805541 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,14 @@
+libpam4j (1.4-3) unstable; urgency=high
+
+  * Team upload.
+  * Fix CVE-2017-12197 (Closes: #879001):
+    It was discovered that libpam4j does not call pam_acct_mgmt().
+    As a consequence, the PAM account is not properly
+    verified. Any user with a valid password but with deactivated or
+    disabled account was able to log in.
+
+ -- Markus Koschany <apo at debian.org>  Tue, 07 Nov 2017 13:40:55 +0100
+
 libpam4j (1.4-2) unstable; urgency=low
 
   * Fix FTBFS (LP: #935254):

-- 
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/pkg-java/libpam4j.git



More information about the pkg-java-commits mailing list