https://seclists.org/oss-sec/2025/q1/26: pam-u2f: problematic PAM_IGNOturn values in pam_sm_authenticate() (CVE-2025-23013)
Published Jan 16, 2025
·Updated
Affected Software
1 affected component
Linux-PAM libpam
Frequently Asked Questions
1
What is the severity of CVE-2025-23013?
CVE-2025-23013 is categorized as a low severity vulnerability due to its limited potential impact.
2
How do I fix CVE-2025-23013?
To fix CVE-2025-23013, update to the latest version of the Linux-PAM library that addresses the vulnerability.
3
What does CVE-2025-23013 affect?
CVE-2025-23013 affects the Linux-PAM library, particularly the handling of PAM_IGNOturn values in the pam_sm_authenticate() function.
4
Can CVE-2025-23013 be exploited remotely?
CVE-2025-23013 is not considered to be remotely exploitable as it requires local access to the system.
5
What are the potential consequences of CVE-2025-23013?
The potential consequences of CVE-2025-23013 include incorrect authentication handling which may lead to authorization failures.