CVE-2011-4120: Input Validation
Yubico PAM Module before 2.10 performed user authentication when 'usefirstpass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2011-4120?
CVE-2011-4120 is a vulnerability in the Yubico PAM Module before version 2.10 that allows a remote attacker to bypass authentication.
How does CVE-2011-4120 affect Debian Linux 8.0?
Debian Linux 8.0 is affected by CVE-2011-4120 if the Yubico PAM module version is older than 2.10.
How does CVE-2011-4120 affect Debian Linux 9.0?
Debian Linux 9.0 is affected by CVE-2011-4120 if the Yubico PAM module version is older than 2.10.
How does CVE-2011-4120 affect Debian Linux 10.0?
Debian Linux 10.0 is affected by CVE-2011-4120 if the Yubico PAM module version is older than 2.10.
How can I fix CVE-2011-4120?
To fix CVE-2011-4120, update the Yubico PAM module to version 2.10 or later.