Just saw the following out on a news site -- I'm not sure if it affects SME Server or not . . . . can someone with more information confirm if this PAM setting is set correctly by default or if it is anything we SME users need to worry about??
---quote---from url
http://www.smh.com.au/articles/2003/06/18/1055828363608.htmlA vulnerability has been identified in Linux-PAM, which allows malicious, local users to escalate their privileges.
PAM stands for Pluggable Authentication Modules, a flexible mechanism for authenticating users.
One module, known as pam_wheel, is often used to allow users belonging to a trusted group to gain root status without supplying a password.
The vulnerability can kick in if the configuration file for pam_wheel has the "trust" option enabled and the "use_uid" option disabled.
Any local user can exploit this vulnerability to spoof log entries, or, in a worst case scenario, obtain super-user privileges.
A workaround suggested by iDefense, the company which revealed the flaw, is to enable the use_uid option in the pam_wheel configuration file.
A version of Linux-PAM which fixes the flaw has already been released.
---end quote---
Thanks,
-Brian