Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2012-6140

N/A

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.

EPSS 0.23% exploit very unlikely percentile 13.8%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Google Authenticator iOS com.google.OTP
    Affected Fixed in Latest tracked undetermined
  • Google Authenticator Android com.google.android.apps.authenticator2
    Affected Fixed in Latest tracked 6.0 undetermined
Vulnerable CPE configurations (6)
Vendor Product Versions
google authenticator
All platforms (wildcard)
≤0.91
google authenticator
All platforms (wildcard)
≤0.91
google authenticator
All platforms (wildcard)
google authenticator
All platforms (wildcard)
google authenticator
All platforms (wildcard)
google authenticator
All platforms (wildcard)
View on NVD ↗