- Update from version 1.7.0 to 1.7.1
- Update of rootfile not required
- This version fixes a CVE. However this is for a local to root permission escalation. So
unlikely to be an issue for IPFire if access is tightly controlled. Also the
vulnerability is related to pam_access and requires the configuration file for that
to be defined with user rules that can be confused with hostnames. pam_access.so is
installed on IPFire but no configuration file.
- Although the risk for IPFire is very low it makes sense to update to the fix.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org> Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>