FS#58119 - [yubico-pam] CVE-2018-9275: Authfile leakage

Attached to Project: Community Packages
Opened by Karol Babioch (kbabioch) - Thursday, 05 April 2018, 07:20 GMT
Last edited by Christian Hesse (eworm) - Thursday, 05 April 2018, 18:37 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Christian Hesse (eworm)
Levente Polyak (anthraxx)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

References:
https://bugzilla.opensuse.org/show_bug.cgi?id=1088027
https://github.com/Yubico/yubico-pam/commit/0f6ceabab0a8849b47f67d727aa526c2656089ba
https://github.com/Yubico/yubico-pam/issues/136
This task depends upon

Closed by  Christian Hesse (eworm)
Thursday, 05 April 2018, 18:37 GMT
Reason for closing:  Fixed
Additional comments about closing:  yubico-pam 2.25-2

Loading...