From d636c1c740d7da16c8d90a68f847e7f1b9bb18797797afe5dedd7747a659abe0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adrian=20Schr=C3=B6ter?= Date: Fri, 7 Feb 2025 18:14:03 +0100 Subject: [PATCH] Sync from SUSE:SLFO:Main pam_u2f revision e97ebb43980ad97931a0f13b4557618b --- pam_u2f-1.3.0.tar.gz | 3 --- pam_u2f-1.3.0.tar.gz.sig | Bin 119 -> 0 bytes pam_u2f-1.3.2.tar.gz | 3 +++ pam_u2f-1.3.2.tar.gz.sig | Bin 0 -> 119 bytes pam_u2f.changes | 12 ++++++++++++ pam_u2f.spec | 4 ++-- 6 files changed, 17 insertions(+), 5 deletions(-) delete mode 100644 pam_u2f-1.3.0.tar.gz delete mode 100644 pam_u2f-1.3.0.tar.gz.sig create mode 100644 pam_u2f-1.3.2.tar.gz create mode 100644 pam_u2f-1.3.2.tar.gz.sig diff --git a/pam_u2f-1.3.0.tar.gz b/pam_u2f-1.3.0.tar.gz deleted file mode 100644 index ee4b5ed..0000000 --- a/pam_u2f-1.3.0.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:72360c6875485eb4df409da8f8f52b17893f05e4d998529c238814480e115220 -size 456281 diff --git a/pam_u2f-1.3.0.tar.gz.sig b/pam_u2f-1.3.0.tar.gz.sig deleted file mode 100644 index ac26fa1d9d7cec7456c8f62a803cdca78fe13f918da25d9a0128b76454f83fb6..0000000000000000000000000000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 119 zcmeAuWnmEGVvrS6WZ7K6{9klI#uDMD+%mRVo==WE*jCKSlp4lA>el6;D!M(K@sY8nS99Q1+ehbaGBTVC`RdWvpu9U_!u10O+)n4H UUb}RW^VmB#^VCVM4se-)Q=dGXk V@PN$|J>~Y75^t>1_pkZK2>|?RGu8kA literal 0 HcmV?d00001 diff --git a/pam_u2f.changes b/pam_u2f.changes index dbf8bdd..7b5b30a 100644 --- a/pam_u2f.changes +++ b/pam_u2f.changes @@ -1,3 +1,15 @@ +------------------------------------------------------------------- +Fri Jan 17 11:19:20 UTC 2025 - Paolo Perego + +- update to 1.3.1: + * Fix incorrect usage of PAM_IGNORE (YSA-2025-01, CVE-2025-23013, bsc#1233517). + * Changed return value when nouserok is enabled and the user has no + credentials, PAM_IGNORE is used instead of PAM_SUCCESS. + * Hardened checks of authfile permissions. + * Hardened checks for nouserok. + * Improved debug messages. + * Improved documentation. + ------------------------------------------------------------------- Sat Apr 15 12:01:02 UTC 2023 - Dirk Müller diff --git a/pam_u2f.spec b/pam_u2f.spec index 0bfae36..ff3551e 100644 --- a/pam_u2f.spec +++ b/pam_u2f.spec @@ -1,7 +1,7 @@ # # spec file for package pam_u2f # -# Copyright (c) 2023 SUSE LLC +# Copyright (c) 2025 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -19,7 +19,7 @@ %{!?_pam_moduledir: %define _pam_moduledir /%{_lib}/security} Name: pam_u2f -Version: 1.3.0 +Version: 1.3.2 Release: 0 Summary: U2F authentication integration into PAM License: BSD-2-Clause