It was found that comments (lines starting with a hash) in /etc/users.oath could prevent one-time-passwords (OTP) from being invalidated, leaving the OTP vulnerable to replay attacks (CVE-2013-7322).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2014-0101.json"