https://seclists.org/oss-sec/2025/q1/24: pam-u2f: problematic PAM_IGNOturn values in pam_sm_authenticate() (CVE-2025-23013)
Published Jan 16, 2025
·Updated
Affected Software
1 affected component
PAM pam-u2f
Frequently Asked Questions
1
What is the severity of CVE-2025-23013?
CVE-2025-23013 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-23013?
To mitigate CVE-2025-23013, ensure that PAM modules are correctly configured and not used for authentication if they do not support it.
3
What systems are affected by CVE-2025-23013?
CVE-2025-23013 affects systems using the PAM pam-u2f module with improper PAM_IGNOturn values.
4
What are the potential impacts of CVE-2025-23013?
The impacts of CVE-2025-23013 include unauthorized access due to improper authentication handling.
5
Can I disable the affected module to mitigate CVE-2025-23013?
Yes, temporarily disabling the pam-u2f module can reduce risk until a proper configuration or patch is applied.