Bug 1213388 - AUDIT-1: pam_dbus: consider dropping this package due to its problematic design
Summary: AUDIT-1: pam_dbus: consider dropping this package due to its problematic design
Status: RESOLVED FIXED
Alias: None
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security (show other bugs)
Version: Current
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-07-17 09:56 UTC by Wolfgang Frisch
Modified: 2024-03-11 09:23 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2023-07-17 09:56:11 UTC
We should have a second look at `pam_dbus` as discussed on IRC last week.
Devel project: Linux-PAM/pam_dbus

The package was last audited 6 years ago [0], where issues have already been raised. On top of that, it uses a D-Bus service configuration ("at_console") that has been deprecated due to possible security issues [1][2][3].

The team's preliminary consensus was that this package should be dropped from openSUSE:Factory and prevented from entering ALP.

[0] https://bugzilla.suse.com/show_bug.cgi?id=1039709
[1] https://www.spinics.net/lists/linux-bluetooth/msg75267.html
[2] https://lintian.debian.org/tags/dbus-policy-at-console
[3] https://devel.fedoraproject.narkive.com/HSrV2HRW/don-t-use-at-console-in-dbus-policy-files
Comment 1 Matthias Gerstner 2023-07-25 13:21:47 UTC
AUDIT-1 should be enough for this topic I guess. There is some time constraint
maybe due to ALP though.
Comment 2 Wolfgang Frisch 2024-03-04 11:01:05 UTC
I will file a delete request.
Comment 3 Wolfgang Frisch 2024-03-04 11:28:35 UTC
In addition to the issues mentioned above, upstream development seems to have ceased. The upstream URL in the spec file [0] and the original Debian package repository [1] do not exist anymore. Debian also dropped it from the distribution a long time ago.

[0] http://git.nomeata.de/?p=darcs-mirror-pam-dbus.debian.git;a=summary
[1] https://people.debian.org/~nomeata/pam-dbus/
[2] https://packages.debian.org/search?searchon=names&keywords=pam-dbus
Comment 4 Wolfgang Frisch 2024-03-04 11:30:05 UTC
https://build.opensuse.org/request/show/1154637
Comment 5 Wolfgang Frisch 2024-03-11 09:23:56 UTC
The delete request was been accepted. Closing.