Vulnerability Bulletins

DSA-3192 checkpw - security update

   
Affected software Debian
 
Hiroya Ito of GMO Pepabo, Inc. reported that checkpw, a passwordauthentication program, has a flaw in processing account names whichcontain double dashes. A remote attacker can use this flaw to cause adenial of service (infinite loop).

More info:

https://www.debian.org/security/2015/dsa-3192