vulnerability

Debian: CVE-2018-9275: yubico-pam -- security update

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:P)
Published
04/04/2018
Added
07/30/2024
Modified
07/30/2024

Description

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

Solution

debian-upgrade-yubico-pam
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.