CVE-2012-6140

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
googleauthenticator
𝑥
≤ 0.91
googleauthenticator
0.86
googleauthenticator
0.87
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
google-authenticator
bookworm
20191231-2
fixed
bullseye
20191231-2
fixed
sid
20191231-2.1
fixed
trixie
20191231-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
google-authenticator
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
ignored
precise
ignored
oneiric
ignored
lucid
dne
hardy
dne