CVE Vulnerabilities

CVE-2012-4571

Published: Nov 30, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

Affected Software

NameVendorStart VersionEnd Version
KeyringPython0.9.1 (including)0.9.1 (including)
Python-keyringUbuntulucid*
Python-keyringUbuntuoneiric*
Python-keyringUbuntuprecise*
Python-keyringUbuntuupstream*

References