{"id":121386,"date":"2025-01-17T15:46:06","date_gmt":"2025-01-17T13:46:06","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena"},"modified":"2025-01-17T15:46:06","modified_gmt":"2025-01-17T13:46:06","slug":"uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans pam-u2f permettant de contourner l'authentification bas\u00e9e sur un jeton mat\u00e9riel","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Les d\u00e9veloppeurs du projet openSUSE ont d\u00e9couvert une vuln\u00e9rabilit\u00e9 (CVE-2025-23013) dans le module PAM pam-u2f, utilis\u00e9 pour l'authentification avec des jetons YubiKey, Yubico Security Key, YubiHSM et d'autres appareils FIDO prenant en charge le protocole U2F (Universal 2nd Factor). Cette vuln\u00e9rabilit\u00e9 permet \u00e0 un utilisateur ayant un acc\u00e8s local non privil\u00e9gi\u00e9 au syst\u00e8me, dans certaines configurations PAM, de s'authentifier sans ins\u00e9rer le jeton mat\u00e9riel. En pratique, le module pam-u2f est g\u00e9n\u00e9ralement utilis\u00e9 pour l'authentification \u00e0 deux facteurs ou sans mot de passe avec des jetons (par exemple, pour confirmer les autorisations d'ex\u00e9cution des commandes via les outils su et sudo).    <\/p>\n<p>La vuln\u00e9rabilit\u00e9 est caus\u00e9e par un retour incorrect de la fonction pam_sm_authenticate() de la valeur PAM_IGNORE. Cette valeur est renvoy\u00e9e en cas d'erreur lors des appels de gethostname(), pam_modutil_drop_priv(), pam_modutil_regain_priv() ou resolve_authfile_path(), ainsi qu\u2019en cas de probl\u00e8mes d\u2019allocation de m\u00e9moire dans strdup() ou calloc(). Le probl\u00e8me est que la biblioth\u00e8que libpam, ayant re\u00e7u du module PAM un r\u00e9sultat avec le code PAM_IGNORE, renverra le code final PAM_SUCCESS, indiquant que l'authentification a r\u00e9ussi, si dans la cha\u00eene de v\u00e9rifications un autre module PAM a renvoy\u00e9 un r\u00e9sultat d'authentification r\u00e9ussi.     <\/p>\n<p>Lors de l'utilisation du module pam-u2f en association avec pam_unix pour l'authentification \u00e0 deux facteurs, la vuln\u00e9rabilit\u00e9 permet de r\u00e9ussir l'authentification lorsque le mot de passe est valid\u00e9, sans confirmation du deuxi\u00e8me facteur. Pour l'authentification sans mot de passe via le jeton mat\u00e9riel, pam-u2f peut \u00eatre utilis\u00e9 en combinaison avec le module PAM pam_faillock, qui limite le nombre de tentatives d'authentification et renvoie PAM_SUCCESS si la limite n'est pas atteinte.       <\/p>\n<p>Un exemple d'attaque serait le contournement de la v\u00e9rification du jeton lors de l'ex\u00e9cution de commandes privil\u00e9gi\u00e9es par un utilisateur local, en utilisant les outils sudo et su. Lors de l'ex\u00e9cution de ces commandes, l'attaquant peut cr\u00e9er des conditions pour que le module pam-u2f renvoie la valeur PAM_IGNORE, par exemple, en \u00e9puisant la m\u00e9moire disponible. Le probl\u00e8me a \u00e9t\u00e9 r\u00e9solu dans la version pam-u2f 1.3.1.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62575\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b U2F (Universal 2nd Factor). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e, \u0438\u043c\u0435\u044e\u0449\u0435\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u0432 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 PAM \u043f\u0440\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0431\u0435\u0437 \u0432\u0441\u0442\u0430\u0432\u043a\u0438 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430. \u041d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435 \u043c\u043e\u0434\u0443\u043b\u044c pam-u2f \u043a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-121386","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pam-u2f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-01-17T13:46:06+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-01-17T13:46:06+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 dans pam-u2f, permettant de contourner l'authentification bas\u00e9e sur le jeton mat\u00e9riel | ProHoster","description":"Les d\u00e9veloppeurs du projet openSUSE ont d\u00e9couvert une vuln\u00e9rabilit\u00e9 (CVE-2025-23013) dans le module PAM pam-u2f, utilis\u00e9 pour l'authentification avec des jetons YubiKey, Yubico Security Key, YubiHSM et d'autres appareils FIDO prenant en charge.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pam-u2f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430 | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-01-17T13:46:06+00:00","article:modified_time":"2025-01-17T13:46:06+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"121386","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 09:45:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 09:45:20","updated":"2026-01-23 09:45:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/121386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=121386"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/121386\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=121386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=121386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=121386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}