<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 16:41:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-02526</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02526</link>
      <description>bdu:2019-02526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02526</guid>
    </item>
    <item>
      <title>cnvd-2019-16864</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-16864</link>
      <description>cnvd-2019-16864</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-16864</guid>
    </item>
    <item>
      <title>EUVD-2026-54874</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-54874</link>
      <description>EUVD-2026-54874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-54874</guid>
    </item>
    <item>
      <title>fkie_cve-2019-12209</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-12209</link>
      <description>&lt;p&gt;Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-12209</guid>
    </item>
    <item>
      <title>GHSA-cf2r-5chq-jmm8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cf2r-5chq-jmm8</link>
      <description>&lt;p&gt;Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cf2r-5chq-jmm8</guid>
    </item>
    <item>
      <title>gsd-2019-12209</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-12209</link>
      <description>gsd-2019-12209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-12209</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:1708-1 — Security update for libu2f-host, pam_u2f</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1708-1</link>
      <description>&lt;p&gt;Security update for libu2f-host, pam_u2f&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libu2f-host, pam_u2f&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:1708-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:1749-1 — Security update for libu2f-host</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:1749-1</link>
      <description>&lt;p&gt;Security update for libu2f-host&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libu2f-host&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:1749-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2019-12209</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12209</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pam-u2f, Ubuntu:Pro:18.04:LTS: pam-u2f&lt;/p&gt;
&lt;p&gt;Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pam-u2f, Ubuntu:Pro:18.04:LTS: pam-u2f&lt;/p&gt;
&lt;p&gt;Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-12209</guid>
    </item>
  </channel>
</rss>
