Vulnerable systems:
Linux Mandrake 6.0, 6.1, 7.0, 7.1, 7.2
The pam_localuser module, which is a part of the pam package, contains a buffer overflow vulnerability. This module is not used in any default configuration and for a user to be exploited, they would have to manually insert it into a configuration file in the /etc/pam.d directory.
Updated packages are available in the "updates/[ver]/RPMS/" directory.
For example, if you are looking for an updated RPM package for Linux-Mandrake 7.2, look for it in "updates/7.2/RPMS/". Updated source RPMs are available as well, but you generally do not need to download them.