{"id":121386,"date":"2025-01-17T15:46:06","date_gmt":"2025-01-17T13:46:06","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena"},"modified":"2025-01-17T15:46:06","modified_gmt":"2025-01-17T13:46:06","slug":"uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","title":{"rendered":"Eine Sicherheitsanf\u00e4lligkeit in pam-u2f, die eine Umgehung der Hardware-Token-Authentifizierung erm\u00f6glicht.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Die Entwickler des openSUSE-Projekts haben eine Sicherheitsanf\u00e4lligkeit (CVE-2025-23013) im PAM-Modul pam-u2f entdeckt, das bei der Authentifizierung \u00fcber YubiKey-Tokens, Yubico Security Key, YubiHSM und andere FIDO-Ger\u00e4te, die das U2F-Protokoll (Universal 2nd Factor) unterst\u00fctzen, verwendet wird. Die Sicherheitsanf\u00e4lligkeit erm\u00f6glicht es einem Benutzer mit nicht privilegiertem lokalem Zugriff auf das System, in bestimmten PAM-Konfigurationen die Authentifizierung ohne Einstecken des Hardware-Tokens durchzuf\u00fchren. In der Praxis wird das Modul pam-u2f in der Regel f\u00fcr die Zwei-Faktor- oder passwortlose Authentifizierung mit Tokens verwendet (zum Beispiel zur Best\u00e4tigung der Berechtigung zur Ausf\u00fchrung von Befehlen \u00fcber die Hilfsprogramme su und sudo).    <\/p>\n<p>Die Sicherheitsanf\u00e4lligkeit wird durch die fehlerhafte R\u00fcckgabe des Wertes PAM_IGNORE durch die Funktion pam_sm_authenticate() verursacht. Dieser Wert wird im Fehlerfall bei den Aufrufen von gethostname(), pam_modutil_drop_priv(), pam_modutil_regain_priv() oder resolve_authfile_path() zur\u00fcckgegeben, sowie bei Problemen mit der Speicherallokation in strdup() oder calloc(). Das Problem besteht darin, dass die Bibliothek libpam, wenn sie von dem PAM-Modul ein Ergebnis mit dem Code PAM_IGNORE erh\u00e4lt, den endg\u00fcltigen Code PAM_SUCCESS zur\u00fcckgibt, der eine erfolgreiche Authentifizierung signalisiert, wenn in der \u00dcberpr\u00fcfungskette ein anderes PAM-Modul ein erfolgreiches Authentifizierungsergebnis zur\u00fcckgegeben hat.     <\/p>\n<p>Bei der Verwendung des pam-u2f-Moduls in Verbindung mit pam_unix f\u00fcr die Zwei-Faktor-Authentifizierung erm\u00f6glicht die Sicherheitsanf\u00e4lligkeit eine erfolgreiche Authentifizierung im Falle einer erfolgreichen Passwort\u00fcberpr\u00fcfung, ohne die Best\u00e4tigung des zweiten Faktors. Bei der Durchf\u00fchrung der passwortlosen Authentifizierung \u00fcber das Hardware-Token kann pam-u2f zusammen mit dem PAM-Modul pam_faillock verwendet werden, das die Anzahl der Authentifizierungsversuche einschr\u00e4nkt und PAM_SUCCESS zur\u00fcckgibt, wenn das Limit nicht \u00fcberschritten wurde.       <\/p>\n<p>Ein Beispiel f\u00fcr einen Angriff ist das Umgehen der Token\u00fcberpr\u00fcfung bei der Ausf\u00fchrung privilegierter Befehle durch einen lokalen Benutzer unter Verwendung der Hilfsprogramme sudo und su. W\u00e4hrend der Ausf\u00fchrung dieser Befehle kann der Angreifer Bedingungen schaffen, die dazu f\u00fchren, dass das Modul pam-u2f den Wert PAM_IGNORE zur\u00fcckgibt, beispielsweise durch das Aussch\u00f6pfen des verf\u00fcgbaren Speichers. Das Problem wurde in der Version pam-u2f 1.3.1 behoben.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62575\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b U2F (Universal 2nd Factor). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e, \u0438\u043c\u0435\u044e\u0449\u0435\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u0432 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 PAM \u043f\u0440\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0431\u0435\u0437 \u0432\u0441\u0442\u0430\u0432\u043a\u0438 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430. \u041d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435 \u043c\u043e\u0434\u0443\u043b\u044c pam-u2f \u043a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-121386","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pam-u2f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-01-17T13:46:06+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-01-17T13:46:06+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Sicherheitsanf\u00e4lligkeit in pam-u2f, die das Umgehen der Authentifizierung auf der Basis von Hardware-Tokens erm\u00f6glicht | ProHoster","description":"Die Entwickler des openSUSE-Projekts haben eine Sicherheitsanf\u00e4lligkeit (CVE-2025-23013) im PAM-Modul pam-u2f entdeckt, das bei der Authentifizierung \u00fcber YubiKey-Tokens, Yubico Security Key, YubiHSM und andere FIDO-Ger\u00e4te, die unterst\u00fctzen.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pam-u2f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430 | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-01-17T13:46:06+00:00","article:modified_time":"2025-01-17T13:46:06+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"121386","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 09:45:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 09:45:20","updated":"2026-01-23 09:45:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/121386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=121386"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/121386\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=121386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=121386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=121386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}