pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=666129 - | |
References | () http://openwall.com/lists/oss-security/2013/04/18/10 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=953505 - Exploit | |
References | () https://code.google.com/p/google-authenticator/source/detail?r=c3414e9857ad64e52283f3266065ef3023fc69a8 - |
Information
Published : 2013-04-24 10:28
Updated : 2025-04-11 00:51
NVD link : CVE-2012-6140
Mitre link : CVE-2012-6140
CVE.ORG link : CVE-2012-6140
JSON object : View
Products Affected
- authenticator
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor