oss-sec mailing list archives

Re: util-linux 2.29.2 fixes CVE-2017-2616


From: Emilio Pozuelo Monfort <pochu () debian org>
Date: Thu, 23 Feb 2017 17:17:28 +0100

On 23/02/17 17:08, Hanno Böck wrote:
On Thu, 23 Feb 2017 07:56:51 -0500
Assaf Gordon <assafgordon () gmail com> wrote:

GNU Coreutils stopped installing 'su' by default in 2007,
and completely removed 'su' (including the 'su.c' source file)
in 2012.

That's good to know, so now there are only 2 competing versions of su
instead of 3 in major packages :-)

Anyone have a good idea who is using shadow vs. util-linux su?

Debian is using shadow's, fwiw.

Emilio


Current thread: