CVE-2012-6140

low
Published 2013-04-24 · Modified 2026-04-29
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-6140

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed20130529-1
debian debianbullseyefixed20130529-1
debian debianforkyfixed20130529-1
debian debiansidfixed20130529-1
debian debiantrixiefixed20130529-1

Application impact

VendorProductVersionsFixed
gcp googleauthenticator{"endIncluding":"0.91"}
gcp googleauthenticator0.86
gcp googleauthenticator0.87

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.