UbuntuUpdates.org

Package "pam-pkcs11"

Name: pam-pkcs11

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Fully featured PAM module for using PKCS#11 smart cards

Latest version: 0.6.12-2ubuntu0.24.10.1
Release: oracular (24.10)
Level: updates
Repository: universe

Links



Other versions of "pam-pkcs11" in Oracular

Repository Area Version
base universe 0.6.12-2build3
security universe 0.6.12-2ubuntu0.24.10.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.6.12-2ubuntu0.24.10.1 2025-03-20 23:06:54 UTC

  pam-pkcs11 (0.6.12-2ubuntu0.24.10.1) oracular-security; urgency=medium

  * SECURITY UPDATE: authentication bypass
    - debian/patches/CVE-2025-24032*.patch: makes the use of signatures to
      verify authentication the default behavior when using X.509
      certificates.
    - CVE-2025-24032
  * SECURITY UPDATE: authentication bypass
    - debian/patches/CVE-2025-24531.patch: changes previously implemented
      default behavior of returning PAM_IGNORE in most cases where
      authentication was not possible.
    - CVE-2025-24531

 -- Ian Constantin <email address hidden> Mon, 03 Mar 2025 16:02:27 +0200

CVE-2025-24032 PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the
CVE-2025-24531 Possible Authentication Bypass in Error Situations



About   -   Send Feedback to @ubuntu_updates