CVE-2012-4571
published 2012-11-30CVE-2012-4571: Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to…
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
29.8th percentile
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-keyring | < python-keyring 0.9.2-1 (bookworm) | python-keyring 0.9.2-1 (bookworm) |
| python | keyring | — | — |
| python | keyring | >= 0 < 0.9.2 | 0.9.2 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python Keyring vulnerabilities
vendor_ubuntu·2012-11-20·CVSS 2.1
CVE-2012-4571 [LOW] Python Keyring vulnerabilities
Title: Python Keyring vulnerabilities
Summary: Several security issues were fixed in Python Keyring.
Dwayne Litzenberger discovered that Python Keyring's CryptedFileKeyring
file format used weak cryptography. A local attacker may use this issue to
brute-force CryptedFileKeyring keyring files. This issue only affected
Ubuntu 11.10 and Ubuntu 12.04 LTS. (CVE-2012-4571)
It was discovered that Python Keyring created keyring files with insecure
permissions. A local attacker could use this issue to access keyring files
belonging to other users.
Instructions: In general, a standard system update will make all the necessary changes.
This update uses a new upstream release, which includes additional bug
fixes, and will migrate existing keyring files to the new format upon first
use.
Red Hat
python-keyring: weak encryption in keyring
vendor_redhat·2012-05-26·CVSS 2.1
CVE-2012-4571 [LOW] CWE-327 python-keyring: weak encryption in keyring
python-keyring: weak encryption in keyring
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Statement: Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform 4.0. This issue is not currently planned to be addressed in future updates.
Package: python-keyring (Red Hat OpenStack Platform 3) - Will not fix
Package: python-keyring (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2012-4571: python-keyring - Python Keyring 0.9.1 does not securely initialize the cipher when encrypting pas...
vendor_debian·2012·CVSS 2.1
CVE-2012-4571 [LOW] CVE-2012-4571: python-keyring - Python Keyring 0.9.1 does not securely initialize the cipher when encrypting pas...
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Scope: local
bookworm: resolved (fixed in 0.9.2-1)
bullseye: resolved (fixed in 0.9.2-1)
forky: resolved (fixed in 0.9.2-1)
sid: resolved (fixed in 0.9.2-1)
trixie: resolved (fixed in 0.9.2-1)
GHSA
Python Keyring does not securely initialize encryption cipher
ghsa·2022-05-17
CVE-2012-4571 [HIGH] CWE-326 Python Keyring does not securely initialize encryption cipher
Python Keyring does not securely initialize encryption cipher
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for `CryptedFileKeyring` files, which makes it easier for local users to obtain passwords via a brute-force attack.
OSV
Python Keyring does not securely initialize encryption cipher
osv·2022-05-17
CVE-2012-4571 [HIGH] Python Keyring does not securely initialize encryption cipher
Python Keyring does not securely initialize encryption cipher
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for `CryptedFileKeyring` files, which makes it easier for local users to obtain passwords via a brute-force attack.
OSV
CVE-2012-4571: Python Keyring 0
osv·2012-11-30·CVSS 2.1
CVE-2012-4571 [LOW] CVE-2012-4571: Python Keyring 0
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
No detection rules found.
Bugzilla
CVE-2012-4571 python-keyring: weak encryption in keyring
bugzilla·2012-11-01·CVSS 2.1
CVE-2012-4571 [LOW] CVE-2012-4571 python-keyring: weak encryption in keyring
CVE-2012-4571 python-keyring: weak encryption in keyring
It was reported [1] that python-keyring prior to version 0.9.1 used the user-supplied password insecurely. This was fixed in 0.9.1 [2] as noted by the following changelog entry:
CryptedFileKeyring now uses PBKDF2 to derive the key from the user's password and a random hash. The IV is chosen randomly as well. All the stored passwords are encrypted at once. Any keyrings using the old format will be automatically converted to the new format (but will no longer be compatible with 0.9 and earlier). The user's password is no longer limited to 32 characters. PyCrypto 2.5 or greater is now required for this keyring.
I'm unsure if we can update everything to this due to the requirement of python-crypto 2.5 (Red Hat Enterprise Linux 6 comes
Bugzilla
CVE-2012-4571 python-keyring: weak encryption in keyring [fedora-all]
bugzilla·2012-11-01·CVSS 2.1
CVE-2012-4571 [LOW] CVE-2012-4571 python-keyring: weak encryption in keyring [fedora-all]
CVE-2012-4571 python-keyring: weak encryption in keyring [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mul
http://pypi.python.org/pypi/keyringhttp://www.openwall.com/lists/oss-security/2012/10/31/8http://www.ubuntu.com/usn/USN-1634-1https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1004845http://pypi.python.org/pypi/keyringhttp://www.openwall.com/lists/oss-security/2012/10/31/8http://www.ubuntu.com/usn/USN-1634-1https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1004845
2012-11-30
Published