PT-2012-4736 · Gnome · Gnome Keyring
Julien Cristau
·
Published
2012-10-22
·
Updated
2013-12-05
·
CVE-2012-3466
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GNOME gnome-keyring versions 3.4.0 through 3.4.1
Description
The issue is related to the caching of passphrases in GNOME gnome-keyring. When the gpg-cache-method is set to "idle" or "timeout", the software does not properly limit the amount of time a passphrase is cached. This could allow attackers to have an unspecified impact, although the exact attack vectors are not specified.
Recommendations
For versions 3.4.0 through 3.4.1, consider changing the gpg-cache-method setting to a more secure option to mitigate the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnome Keyring