{ "schema_version": "1.4.0", "id": "GHSA-cq7j-cjrf-2r4m", "modified": "2022-05-17T05:10:25Z", "published": "2022-05-17T05:10:25Z", "aliases": [ "CVE-2012-6140" ], "details": "pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-6140" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=953505" }, { "type": "WEB", "url": "https://code.google.com/p/google-authenticator/source/detail?r=c3414e9857ad64e52283f3266065ef3023fc69a8" }, { "type": "WEB", "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=666129" }, { "type": "WEB", "url": "http://openwall.com/lists/oss-security/2013/04/18/10" } ], "database_specific": { "cwe_ids": [ "CWE-200" ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2013-04-24T10:28:00Z" } }