First published: Mon Feb 10 2025(Updated: )
Last updated 20 March 2025
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
PAM-PKCS#11 | <0.6.13>=0.6.0 | |
debian/pam-pkcs11 | <=0.6.11-4 | 0.6.11-4+deb11u1 0.6.12-1+deb12u1 0.6.13-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24032 is classified as a high severity vulnerability due to the potential for unauthorized access.
To mitigate CVE-2025-24032, upgrade PAM-PKCS#11 to version 0.6.13 or later.
CVE-2025-24032 allows attackers to exploit user login capabilities if cert_policy is set to none, potentially leading to unauthorized access.
If you are running PAM-PKCS#11 versions earlier than 0.6.13, your system is vulnerable to CVE-2025-24032.
CVE-2025-24032 affects PAM-PKCS#11 versions from 0.6.0 up to, but not including, 0.6.13.