Am I mistaken or is pam_xauth not used in Debian? This might mean that CVE-2010-4707 and CVE-2010-4706 do not affect Debian.
cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de)
signature.asc
Description: Digital signature