pam_motd patch to show /etc/legal fails to set flag

Bug #481854 reported by Bernhard Seibold
16
This bug affects 3 people
Affects Status Importance Assigned to Milestone
pam (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

The annoying patch added to pam_motd to show /etc/legal on first login tries to create a file in the user's home directory.

On systems where the home directories are NOT accessible by root (i.e. nfs-mounted with root-squashing or kerberos) that fails, and the annoying legalese is shown every time one logs in.

CVE References

Revision history for this message
Bernhard Seibold (blubb8128) wrote :

It would be nice to do it the other way around: create a flag-file in /etc/skel and delete it from the user's home after showing /etc/legal.

Or at least don't show the legalese if the directory containing the flag can't be accessed at all.

Changed in pam (Ubuntu):
status: New → Confirmed
Revision history for this message
Steve Langasek (vorlon) wrote :

This bug has been fixed in later versions of pam_motd as a side effect of fixing CVE-2010-0832.

Changed in pam (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.