https://seclists.org/oss-sec/2025/q1/21: pam-u2f: problematic PAM_IGNOturn values in pam_sm_authenticate() (CVE-2025-23013)
Published Jan 15, 2025
·Updated
Affected Software
1 affected component
openSUSE pam-u2f
Frequently Asked Questions
1
What is the severity of CVE-2025-23013?
CVE-2025-23013 is considered a medium severity vulnerability due to its impact on PAM authentication.
2
How do I fix CVE-2025-23013?
To mitigate CVE-2025-23013, update to the latest version of the pam-u2f module that addresses the problematic PAM_IGNOturn values.
3
What systems are affected by CVE-2025-23013?
CVE-2025-23013 affects the pam-u2f module used in openSUSE and potentially other systems utilizing this authentication method.
4
What is pam-u2f in relation to CVE-2025-23013?
Pam-u2f is a PAM module that enables the use of U2F devices for two-factor authentication, which is affected by CVE-2025-23013.
5
What are the implications of CVE-2025-23013 for user authentication?
CVE-2025-23013 may lead to improper handling of authentication return values, potentially allowing unauthorized access.