- fix CVE-2014-2583: potential path traversal issue in pam_timestamp - fix CVE-2013-7041: use case sensitive comparison in pam_userdb - be tolerant to corrupted opasswd file