📦

yubico_pam

Vendor: yubico

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 1.47% Exploit Prob.
Latest CVE CVE-2018-9275 Apr 04

Security Vulnerability Index

Page 1 / 1
8.2 CVSS

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

EPSS: 1.47%