Package: libpam-pgsql
Tags: security

Lucas Clemente Vella discovered that pam-pgsql (aka pam_pgsql) might
allow login with any password the SQL query for the password returns
NULL.

Bug report: <https://sourceforge.net/p/pam-pgsql/bugs/13/>
Patch: 
<https://sourceforge.net/u/lvella/pam-pgsql/ci/9361f5970e5dd90a747319995b67c2f73b91448c/>

Please fix this for squeeze and wheezy, using minimal fixes.
(We will not release a DSA for this.)


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to