Description
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-0012 | Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack. |
Github GHSA |
GHSA-p3h7-3c45-qj4v | Python Keyring does not securely initialize encryption cipher |
Ubuntu USN |
USN-1634-1 | Python Keyring vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-17T03:07:17.992Z
Reserved: 2012-08-21T00:00:00.000Z
Link: CVE-2012-4571
No data.
Status : Modified
Published: 2012-11-30T22:55:01.830
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-4571
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN