Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24jw-8jpm-q7p5

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

EPSS

Процентиль: 65%
0.00492
Низкий

8.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 7 лет назад

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

CVSS3: 8.2
nvd
больше 7 лет назад

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

CVSS3: 8.2
debian
больше 7 лет назад

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico ...

EPSS

Процентиль: 65%
0.00492
Низкий

8.2 High

CVSS3

Дефекты

CWE-200