Errata ID | 206 |
---|---|
Date | 2019-07-31 |
Source package | pam |
Fixed in version | 1.1.8-3.6A~4.4.0.201907171120 |
Description | This update addresses the following issue: * pam_unix now strips passwords at 512 characters. This prevents denial of service attacks when authenticating with very long passwords when pam_unix would hang in the hashsum generation of the password. https://github.com/linux-pam/linux-pam/issues/118 |
Additional notes | |
UCS Bug number | #49741 |