CVE-2018-9275: Infoleak
Published Apr 4, 2018
·Updated
In checkusertoken in util.c in the Yubico PAM module (aka pamyubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).
Affected Software
1 affected component
Yubico Yubico Pam Yubico>=2.18<=2.25
Remediation
Event History
Apr 4, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID is CVE-2018-9275.
2
What is the severity rating for CVE-2018-9275?
The severity rating for CVE-2018-9275 is high (8.2).
3
What is the affected software?
The affected software is Yubico Pam version 2.18 through 2.25.
4
What are the potential consequences of this vulnerability?
This vulnerability can lead to information disclosure (serial number of a device) and/or Denial of Service (DoS) by reaching the maximum number of file descriptors.
5
Are there any fixes or patches available?
Yes, fixes for this vulnerability are available. Please refer to the provided references for more information.