Copied from
ubuntu trusty in
Private PPA for Ubuntu Security Team
by Steve Beattie
Changelog
libpam-sshauth (0.3.1-1deb8u1build0.14.04.1) trusty-security; urgency=medium
* fake sync from Debian
libpam-sshauth (0.3.1-1+deb8u1) jessie-security; urgency=high
* Non-maintainer upload by the Security Team.
* CVE-2016-4422: local root privilege escalation.
Return PAM_AUTH_ERR when a system user. This prevents the pam module
from returning success without asking for authentication credentials.
Thanks to Vagrant Cascadian <email address hidden>
-- Steve Beattie <email address hidden> Fri, 20 May 2016 23:36:30 -0700