PT-2012-4736 · Gnome · Gnome Keyring
Julien Cristau
·
Publicado
2012-10-22
·
Atualizado
2013-12-05
·
CVE-2012-3466
CVSS v2.0
4.4
Média
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNOME gnome-keyring versions 3.4.0 through 3.4.1
Description
The issue is related to the caching of passphrases in GNOME gnome-keyring. When the gpg-cache-method is set to "idle" or "timeout", the software does not properly limit the amount of time a passphrase is cached. This could allow attackers to have an unspecified impact, although the exact attack vectors are not specified.
Recommendations
For versions 3.4.0 through 3.4.1, consider changing the gpg-cache-method setting to a more secure option to mitigate the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gnome Keyring