CVE-2012-4571
Publication date 6 November 2012
Last updated 24 July 2024
Ubuntu priority
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-keyring | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Fixed 0.9.2-0ubuntu0.12.04.2
|
|
11.10 oneiric |
Fixed 0.9.2-0ubuntu0.11.10.2
|
|
10.04 LTS lucid | Ignored end of life | |
8.04 LTS hardy | Not in release |
References
Related Ubuntu Security Notices (USN)
- USN-1634-1
- Python Keyring vulnerabilities
- 20 November 2012