Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 948201 (CVE-2025-23013, YSA-2025-01) - <sys-auth/pam_u2f-1.3.2: Partial Authentication Bypass
Summary: <sys-auth/pam_u2f-1.3.2: Partial Authentication Bypass
Status: IN_PROGRESS
Alias: CVE-2025-23013, YSA-2025-01
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://www.yubico.com/support/securi...
Whiteboard: B1 [glsa+ cleanup]
Keywords:
Depends on: 948423
Blocks:
  Show dependency tree
 
Reported: 2025-01-16 19:29 UTC by genBTC
Modified: 2025-01-23 06:16 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description genBTC 2025-01-16 19:29:04 UTC
sys-auth/pam_u2f prior to version 1.3.1 is affected by this vuln

2025-01-14	Yubico releases advisory YSA-2025-01
https://www.yubico.com/support/security-advisories/ysa-2025-01/

also known as CVE: CVE-2025-23013
Published Date: 2025-01-14
Tracking IDs: YSA-2025-01
CVSS Severity: 7.3

Reproducible: Always
Comment 1 Larry the Git Cow gentoo-dev 2025-01-19 22:53:47 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ab3c19d764f6dcc5f736dfc7df06a3d908ed6c5b

commit ab3c19d764f6dcc5f736dfc7df06a3d908ed6c5b
Author:     Matt Jolly <kangie@gentoo.org>
AuthorDate: 2025-01-19 22:49:56 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2025-01-19 22:50:37 +0000

    sys-auth/pam_u2f: add 1.3.2
    
    Bug: https://bugs.gentoo.org/948201
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 sys-auth/pam_u2f/Manifest             |  1 +
 sys-auth/pam_u2f/pam_u2f-1.3.2.ebuild | 27 +++++++++++++++++++++++++++
 2 files changed, 28 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2025-01-23 06:15:16 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=bb937b5a5b189acfa5ffeb196db894e00784c57f

commit bb937b5a5b189acfa5ffeb196db894e00784c57f
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2025-01-23 06:15:02 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2025-01-23 06:15:14 +0000

    [ GLSA 202501-04 ] Yubico pam-u2f: Partial Authentication Bypass
    
    Bug: https://bugs.gentoo.org/948201
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202501-04.xml | 43 +++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 43 insertions(+)