Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Keyring | Python | 0.9.1 (including) | 0.9.1 (including) |
Python-keyring | Ubuntu | lucid | * |
Python-keyring | Ubuntu | oneiric | * |
Python-keyring | Ubuntu | precise | * |
Python-keyring | Ubuntu | upstream | * |