Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4571

Опубликовано: 26 мая 2012
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

Отчет

Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform 4.0. This issue is not currently planned to be addressed in future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3python-keyringWill not fix
Red Hat OpenStack Platform 4python-keyringWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=872260python-keyring: weak encryption in keyring

EPSS

Процентиль: 30%
0.0037
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

nvd
больше 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

debian
больше 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encr ...

CVSS3: 7.5
github
около 4 лет назад

Python Keyring does not securely initialize encryption cipher

EPSS

Процентиль: 30%
0.0037
Низкий

2.1 Low

CVSS2