Back

HIGH

python-keyring: weak encryption in keyring

Published Nov 30, 2012

Description

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform 4.0. This issue is not currently planned to be addressed in future updates.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 30, 2012
Updated Sep 17, 2024
Reserved Aug 21, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 26, 2012
GHSA-P3H7-3C45-QJ4V