FS#68945 - [at][gdm][pambase] user_readenv is deprecated
Attached to Project:
Arch Linux
Opened by Geert Hendrickx (ghen) - Friday, 11 December 2020, 15:54 GMT
Last edited by David Runge (dvzrv) - Friday, 21 October 2022, 09:26 GMT
Opened by Geert Hendrickx (ghen) - Friday, 11 December 2020, 15:54 GMT
Last edited by David Runge (dvzrv) - Friday, 21 October 2022, 09:26 GMT
|
Details
pambase installs /etc/pam.d/system-login containing the
following line:
session required pam_env.so user_readenv=1 According to pam_env(8), user_readenv is deprecated for security reasons, so since upgrading to pam 1.5.0, my systemd journal is full of: systemd[22414]: pam_env(systemd-user:session): deprecated reading of user environment enabled lightdm[22409]: pam_env(lightdm:session): deprecated reading of user environment enabled sshd[23040]: pam_env(sshd:session): deprecated reading of user environment enabled I'm no expert on the matter and I don't know why this was enabled in Arch, but it's probably best to reconsider this. |
This task depends upon
Closed by David Runge (dvzrv)
Friday, 21 October 2022, 09:26 GMT
Reason for closing: Fixed
Additional comments about closing: Fixed with at 3.2.5-2, gdm 43.0-1, pambase 20221020-1.
Friday, 21 October 2022, 09:26 GMT
Reason for closing: Fixed
Additional comments about closing: Fixed with at 3.2.5-2, gdm 43.0-1, pambase 20221020-1.
Package | pam file
at : atd
gdm : gdm-launch-environment
FS#67519for why it was added.https://nvd.nist.gov/vuln/detail/CVE-2015-8325
I have removed the setting from pambase [2] and will issue a release in [testing] today.
[1] https://github.com/linux-pam/linux-pam/blob/f69a6042da801096c94b30465c118e17c803f5c2/NEWS#L38-L39
[2] https://github.com/archlinux/svntogit-packages/commit/b9d1d5e6e62834ca97afe2023468d19d9faccad7