{"id":121386,"date":"2025-01-17T15:46:06","date_gmt":"2025-01-17T13:46:06","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena"},"modified":"2025-01-17T15:46:06","modified_gmt":"2025-01-17T13:46:06","slug":"uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","title":{"rendered":"Vulnerabilitate \u00een pam-u2f, care permite ocolirea autentific\u0103rii bazate pe token hardware.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dezvoltatorii proiectului openSUSE au identificat o vulnerabilitate (CVE-2025-23013) \u00een modulul PAM pam-u2f, utilizat pentru autentificare cu tokenuri YubiKey, Yubico Security Key, YubiHSM \u0219i alte dispozitive FIDO care suport\u0103 protocolul U2F (Universal 2nd Factor). Vulnerabilitatea permite unui utilizator cu acces local neprivilegiat la sistem, \u00een anumite configura\u021bii PAM, s\u0103 treac\u0103 autentificarea f\u0103r\u0103 a insera tokenul hardware. \u00cen practic\u0103, modulul pam-u2f este de obicei conectat pentru autentificarea cu doi factori sau f\u0103r\u0103 parol\u0103 folosind tokenuri (de exemplu, pentru a confirma dreptul de a executa comenzi prin utilitarele su \u0219i sudo).    <\/p>\n<p>Vulnerabilitatea este cauzat\u0103 de returnarea incorect\u0103 a valorii PAM_IGNORE de c\u0103tre func\u021bia pam_sm_authenticate(). Aceast\u0103 valoare este returnat\u0103 \u00een caz de eroare la executarea apelurilor gethostname(), pam_modutil_drop_priv(), pam_modutil_regain_priv() sau resolve_authfile_path(), precum \u0219i \u00een caz de probleme de alocare a memoriei \u00een strdup() sau calloc(). Problema const\u0103 \u00een faptul c\u0103 biblioteca libpam, primind de la modulul PAM un rezultat cu codul PAM_IGNORE, va returna codul final PAM_SUCCESS, care indic\u0103 o autentificare reu\u0219it\u0103, dac\u0103 \u00een lan\u021bul de verific\u0103ri un alt modul PAM a returnat un rezultat pozitiv al autentific\u0103rii.     <\/p>\n<p>Atunci c\u00e2nd se folose\u0219te modulul pam-u2f \u00een tandem cu pam_unix pentru autentificare cu doi factori, vulnerabilitatea permite trecerea cu succes a autentific\u0103rii \u00een cazul unei verific\u0103ri reu\u0219ite a parolei, f\u0103r\u0103 confirmarea celui de-al doilea factor. \u00cen cazul autentific\u0103rii f\u0103r\u0103 parol\u0103 cu un token hardware, pam-u2f poate fi utilizat \u00een combina\u021bie cu modulul PAM pam_faillock, care limiteaz\u0103 num\u0103rul de \u00eencerc\u0103ri de autentificare \u0219i returneaz\u0103 PAM_SUCCESS, dac\u0103 limita nu a fost atins\u0103.       <\/p>\n<p>Un exemplu de atac este ocolirea verific\u0103rii tokenului atunci c\u00e2nd un utilizator local execut\u0103 comenzi privilegiate, folosind utilitarele sudo \u0219i su. \u00cen timpul rul\u0103rii acestor comenzi, atacatorul poate crea condi\u021bii pentru returnarea de c\u0103tre modulul pam-u2f a valorii PAM_IGNORE, de exemplu, prin epuizarea memoriei disponibile. Problema a fost rezolvat\u0103 \u00een versiunea pam-u2f 1.3.1.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=62575\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b U2F (Universal 2nd Factor). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e, \u0438\u043c\u0435\u044e\u0449\u0435\u043c\u0443 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u0432 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 PAM \u043f\u0440\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u0431\u0435\u0437 \u0432\u0441\u0442\u0430\u0432\u043a\u0438 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430. \u041d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435 \u043c\u043e\u0434\u0443\u043b\u044c pam-u2f \u043a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0434\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-121386","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pam-u2f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-01-17T13:46:06+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-01-17T13:46:06+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een pam-u2f care permite ocolirea autentific\u0103rii bazate pe token hardware | ProHoster","description":"Dezvoltatorii proiectului openSUSE au identificat o vulnerabilitate (CVE-2025-23013) \u00een modulul PAM pam-u2f, utilizat pentru autentificare cu tokenuri YubiKey, Yubico Security Key, YubiHSM \u0219i alte dispozitive FIDO care suport\u0103.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 pam-u2f, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044e \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0442\u043e\u043a\u0435\u043d\u0430 | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 openSUSE \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2025-23013) \u0432 PAM-\u043c\u043e\u0434\u0443\u043b\u0435 pam-u2f, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u043f\u0440\u0438 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 \u0442\u043e\u043a\u0435\u043d\u044b YubiKey, Yubico Security Key, YubiHSM \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 FIDO-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0435.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-pam-u2f-pozvolyayushhaya-obojti-autentifikacziyu-na-baze-apparatnogo-tokena","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-01-17T13:46:06+00:00","article:modified_time":"2025-01-17T13:46:06+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"121386","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 09:45:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 09:45:20","updated":"2026-01-23 09:45:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/121386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=121386"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/121386\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=121386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=121386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=121386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}