Bug#1018260: openssh-server: fills the log with "deprecated reading of user environment enabled"

Laura Smith <[email protected]>
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <kAJZounKFTCHdhLcfYH9YBpZ0EKCAzaxbNxjBjJ6WbiowQXzsqbdwp69_LsVIRzOaYrtqhSSllAfz3P1LwNB2-8AN8SX9O_lNM6Gcwjywj8=__20288.6547356442$1716042267$gmane$org@protonmail.ch>
You wanted to "track down an actual reason for this change" ?

Try this:

CVE-2011-3148
CVE-2011-3149

As summarised by Redhat (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/6.4_technical_notes/pam):

If an application's PAM configuration contained user_readenv=1, a local attacker could use this flaw to cause the application to enter an infinite loop.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.