CVE-2012-2760

low
Published 2012-07-25 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2760

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/49247

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed0.7-0.1

Application impact

VendorProductVersionsFixed
findingsciencemod_auth_openid{"endIncluding":"0.6"}
findingsciencemod_auth_openid0.1
findingsciencemod_auth_openid0.2
findingsciencemod_auth_openid0.2.1
findingsciencemod_auth_openid0.3
findingsciencemod_auth_openid0.4
findingsciencemod_auth_openid0.5

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.