[gnome-keyring] [pam] Do not leak login name when logging error



commit ae1c102543acc4b6c607cb1462107b8a4d4409d3
Author: Laurent Bigonville <l bigonville edpnet be>
Date:   Wed Mar 9 19:42:17 2011 +0100

    [pam] Do not leak login name when logging error
    
    Don't include unrecognized user names in log messages, as they
    could be mistyped passwords.

 pam/gkr-pam-module.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)
---
diff --git a/pam/gkr-pam-module.c b/pam/gkr-pam-module.c
index d6fc17d..e63c917 100644
--- a/pam/gkr-pam-module.c
+++ b/pam/gkr-pam-module.c
@@ -815,7 +815,7 @@ pam_sm_authenticate (pam_handle_t *ph, int unused, int argc, const char **argv)
 	
 	pwd = getpwnam (user);
 	if (!pwd) {
-		syslog (GKR_LOG_ERR, "gkr-pam: error looking up user information for: %s", user);
+		syslog (GKR_LOG_ERR, "gkr-pam: error looking up user information");
 		return PAM_SERVICE_ERR;
 	}
 		



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]