oss-sec mailing list archives

Re: util-linux 2.29.2 fixes CVE-2017-2616


From: Hanno Böck <hanno () hboeck de>
Date: Thu, 23 Feb 2017 17:08:48 +0100

On Thu, 23 Feb 2017 07:56:51 -0500
Assaf Gordon <assafgordon () gmail com> wrote:

GNU Coreutils stopped installing 'su' by default in 2007,
and completely removed 'su' (including the 'su.c' source file)
in 2012.

That's good to know, so now there are only 2 competing versions of su
instead of 3 in major packages :-)

Anyone have a good idea who is using shadow vs. util-linux su? Do they
have specific advantages/disadvantages, would it be reasonable to try
to get all distros to use them same one?

-- 
Hanno Böck
https://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: FE73757FA60E4E21B937579FA5880072BBB51E42


Current thread: