Yubico PAM module 2.4

CPE Details

Yubico PAM module 2.4
2.4
2019-12-17
11h31 +00:00
2019-12-17
11h31 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:yubico:pam_module:2.4:*:*:*:*:*:*:*

Informations

Vendor

yubico

Product

pam_module

Version

2.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2011-4120 2019-11-26 03h17 +00:00 Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
9.8
Critical