Executive Summary

Informations
Name CVE-2025-24032 First vendor Publication 2025-02-10
Vendor Cve Last vendor Modification 2025-02-18

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the default value), then pam_pkcs11 will only check if the user is capable of logging into the token. An attacker may create a different token with the user's public data (e.g. the user's certificate) and a PIN known to the attacker. If no signature with the private key is required, then the attacker may now login as user with that created token. The default to *not* check the private key's signature has been changed with commit commi6638576892b59a99389043c90a1e7dd4d783b921, so that all versions starting with pam_pkcs11-0.6.0 should be affected. As a workaround, in `pam_pkcs11.conf`, set at least `cert_policy = signature;`.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24032

Sources (Detail)

https://github.com/OpenSC/pam_pkcs11/commit/470263258d1ac59c5eade439c4d9caba0...
https://github.com/OpenSC/pam_pkcs11/commit/b665b287ff955bbbd9539252ff9f9e275...
https://github.com/OpenSC/pam_pkcs11/commit/d9530167966a77115db6e885d459382a2...
https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13
https://github.com/OpenSC/pam_pkcs11/security/advisories/GHSA-8r8p-7mgp-vf56
https://lists.debian.org/debian-lts-announce/2025/02/msg00021.html
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2025-02-18 17:20:34
  • Multiple Updates
2025-02-10 21:20:29
  • First insertion