Matthias Gerstner reported that pam-u2f, a PAM module which allows to use U2F (Universal 2nd Factor) devices in the PAM authentication stack, does not properly handle PAM_IGNORE return values, allowing to bypass the second factor or password-less login without inserting the proper device.
https://security-tracker.debian.org/tracker/DSA-5853-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-5853-1
Continue reading...

