6.4
CVSSv2

CVE-2018-9275

Published: 04/04/2018 Updated: 21/05/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 up to and including 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

Vulnerable Product Search on Vulmon Subscribe to Product

yubico yubico pam

Vendor Advisories

Debian Bug report logs - #896491 yubico-pam: CVE-2018-9275: Authfile Leaking File Descriptor Package: src:yubico-pam; Maintainer for src:yubico-pam is Debian Authentication Maintainers <pkg-auth-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 21 Apr 2018 17:21:02 ...