[Pkg-shadow-devel] Bug#914957: additional

russm russm-debian-bugs at slofith.org
Thu Nov 29 03:44:40 GMT 2018


Specifically, the current status means that on stretch systems, any
accounts relying on the default pam_unix nullok_secure to allow null-
password accounts to log in from local terminals only are open to access
by anyone who ssh's in and happens to get get pts/0 or pts/1.



More information about the Pkg-shadow-devel mailing list