FS#58119 - [yubico-pam] CVE-2018-9275: Authfile leakage
Attached to Project:
Community Packages
Opened by Karol Babioch (kbabioch) - Thursday, 05 April 2018, 07:20 GMT
Last edited by Christian Hesse (eworm) - Thursday, 05 April 2018, 18:37 GMT
Opened by Karol Babioch (kbabioch) - Thursday, 05 April 2018, 07:20 GMT
Last edited by Christian Hesse (eworm) - Thursday, 05 April 2018, 18:37 GMT
|
Details
In check_user_token in util.c in the Yubico PAM module (aka
pam_yubico) 2.18 through 2.25, successful logins can leak
file descriptors to the auth mapping file, which can lead to
information disclosure (serial number of a device) and/or
DoS (reaching the maximum number of file descriptors).
References: https://bugzilla.opensuse.org/show_bug.cgi?id=1088027 https://github.com/Yubico/yubico-pam/commit/0f6ceabab0a8849b47f67d727aa526c2656089ba https://github.com/Yubico/yubico-pam/issues/136 |
This task depends upon
Closed by Christian Hesse (eworm)
Thursday, 05 April 2018, 18:37 GMT
Reason for closing: Fixed
Additional comments about closing: yubico-pam 2.25-2
Thursday, 05 April 2018, 18:37 GMT
Reason for closing: Fixed
Additional comments about closing: yubico-pam 2.25-2