PT-2012-4736 · Gnome · Gnome Keyring

Julien Cristau

·

Published

2012-10-22

·

Updated

2013-12-05

·

CVE-2012-3466

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNOME gnome-keyring versions 3.4.0 through 3.4.1
Description The issue is related to the caching of passphrases in GNOME gnome-keyring. When the gpg-cache-method is set to "idle" or "timeout", the software does not properly limit the amount of time a passphrase is cached. This could allow attackers to have an unspecified impact, although the exact attack vectors are not specified.
Recommendations For versions 3.4.0 through 3.4.1, consider changing the gpg-cache-method setting to a more secure option to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3466
OPENSUSE-SU-2024:10560-1

Affected Products

Gnome Keyring