1.9
CVSSv2

CVE-2012-6140

Published: 24/04/2013 Updated: 07/05/2013
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

pam_google_authenticator.c in the PAM module in Google Authenticator prior to 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.

Vulnerable Product Search on Vulmon Subscribe to Product

google authenticator 0.87

google authenticator 0.86

google authenticator

Vendor Advisories

Debian Bug report logs - #666129 new upstream version fixes security problem with the secret file (CVE-2012-6140) Package: libpam-google-authenticator; Maintainer for libpam-google-authenticator is Janos Lenart <ocsi@debianorg>; Source for libpam-google-authenticator is src:google-authenticator (PTS, buildd, popcon) Reporte ...