VDB
CVE-2012-6140
CVE-2012-6140
PUBLISHED
CVSS 1.899999976158142 LOW
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.
EPSS 0.23% · 14.1th percentile
Risk Scores
CVSS 2.0
1.899999976158142
EPSS Score
0.23%
14.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| authenticator | 0.86, 0.87, 0 |
Timeline
- Apr 24, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=953505 url
- [oss-security] 20130418 Re: CVE-2012-XXYY Request -- google-authenticator: Information disclosure due insecure requirement on the secrets file mailing-list
- https://code.google.com/p/google-authenticator/source/detail?r=c3414e9857ad64e52283f3266065ef3023fc69a8 url
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=666129 url
- https://nvd.nist.gov/vuln/detail/CVE-2012-6140 advisory