Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-23013

Опубликовано: 15 янв. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

РелизСтатусПримечание
devel

not-affected

1.3.1-1
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

released

1.0.8-1ubuntu0.1~esm1
esm-apps/jammy

released

1.1.0-1.1+deb12u1build0.22.04.1
esm-apps/noble

released

1.1.0-1.1+deb12u1build0.24.04.1
esm-apps/xenial

ignored

changes too intrusive
focal

ignored

end of standard support, was needs-triage
jammy

released

1.1.0-1.1+deb12u1build0.22.04.1
noble

released

1.1.0-1.1+deb12u1build0.24.04.1
oracular

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 24%
0.00079
Низкий

Связанные уязвимости

nvd
11 месяцев назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software package has an issue that allows for an authentication bypass in some configurations. An attacker would require the ability to access the system as an unprivileged user. Depending on the configuration, the attacker may also need to know the user's password.

debian
11 месяцев назад

In Yubico pam-u2f before 1.3.1, local privilege escalation can sometim ...

suse-cvrf
10 месяцев назад

Security update for pam_u2f

suse-cvrf
10 месяцев назад

Security update for pam_u2f

suse-cvrf
11 месяцев назад

Security update for pam_u2f

EPSS

Процентиль: 24%
0.00079
Низкий