Re: PAM exec patch to allow PAM_AUTHTOK to be exported.



On Sun, 20 May 2007 19:10:33 +0200
Dag-Erling Smørgrav <des@xxxxxx> wrote:

"Zane C.B." <v.velox@xxxxxxxxxx> writes:
Dag-Erling Smørgrav <des@xxxxxx> writes:
Your patch opens a gaping security hole. Sensitive information
should never be placed in the environment.
Unless I am missing something, this is only dangerous if one is
doing something stupid with what ever is being executed by
pam_exec.

Environment variables may be visible to other processes and users
through e.g. /proc.

Cool. Forgot about /proc. Is definitely a issue. Hmmm, any ideas in
the area of passing it then?

My current thoughts are along the lines of passing it through stdin
currently.
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"

Relevant Pages

  • Re: PAM exec patch to allow PAM_AUTHTOK to be exported.
    ... Unless I am missing something, this is only dangerous if one is doing ... something stupid with what ever is being executed by pam_exec. ... Environment variables may be visible to other processes and users ... Dag-Erling Smørgrav - des@xxxxxx ...
    (FreeBSD-Security)
  • Re: IQ and race: maybe its environment
    ... I would say that most people's brain function is irrelevant to intelligence. ... people around me had ADEQUATE environments and have achieved their ... you find most people to be stupid. ... both that they are stupid and that their environment was adequate, ...
    (rec.martial-arts)
  • Re: Comparing 2 recordsets to get Missing or Different
    ... By MISSING I believe you mean there is only one row meeting the criteria. ... > Environment names are like REGNHIM, PRODHIM, STSTHI1, etc... ... >> to let some SQL code do the walking. ... >> tblAIPProfileVariables T2 ...
    (microsoft.public.access.queries)
  • Re: 2.6.24-rc1-82798a1 compile failure (x86_64)
    ... even potentially the kernel build. ... I definitely think the new kbuild CFLAGS behavior is just fine. ... If people do stupid things in their environment without being willing ... Say this stupid CFLAGS ...
    (Linux-Kernel)
  • [opensuse] Re: problems building perl 5.14.2 or 5.16.0 using RPMBUILD, build from tar or perlbrew (a
    ... Where did I say that cpp46 was missing? ... environment and b) resolves all requirements if stated correctly. ... OBS causes problems. ... Well after the cc1 'compiler' applies macros and tokenizes the ...
    (SuSE)