<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="19eded2f1b85d76a42034869fdd319b4"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="427">
  <id>dbg111-pam_mount</id>
  <title>pam_mount: fixes passwdehd script symlink attack</title>
  <release>openSUSE 11.1</release>
  <issued date="1231919819"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=465303" id="465303" title="bug number 465303" type="bugzilla"/>
  </references>
  <description>This update fixes the temp-flle handling in the passwdehd
script that allowed a symlink attack. (CVE-2008-5138)
(script was disabled for 11.0 and 11.1)
</description>
  <pkglist>
    <collection>
        <package name="pam_mount-debuginfo" arch="i586" version="0.47" release="12.14.1">
          <filename>pam_mount-debuginfo-0.47-12.14.1.i586.rpm</filename>
        </package>
        <package name="pam_mount-debuginfo" arch="ppc" version="0.47" release="12.14.1">
          <filename>pam_mount-debuginfo-0.47-12.14.1.ppc.rpm</filename>
        </package>
        <package name="pam_mount-debuginfo" arch="x86_64" version="0.47" release="12.14.1">
          <filename>pam_mount-debuginfo-0.47-12.14.1.x86_64.rpm</filename>
        </package>
        <package name="pam_mount-debugsource" arch="i586" version="0.47" release="12.14.1">
          <filename>pam_mount-debugsource-0.47-12.14.1.i586.rpm</filename>
        </package>
        <package name="pam_mount-debugsource" arch="ppc" version="0.47" release="12.14.1">
          <filename>pam_mount-debugsource-0.47-12.14.1.ppc.rpm</filename>
        </package>
        <package name="pam_mount-debugsource" arch="x86_64" version="0.47" release="12.14.1">
          <filename>pam_mount-debugsource-0.47-12.14.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
