Summary
Ubuntu Update for Linux kernel vulnerabilities USN-1634-1
Solution
Please Install the Updated Packages.
Insight
Dwayne Litzenberger discovered that Python Keyring's CryptedFileKeyring file format used weak cryptography. A local attacker may use this issue to brute-force CryptedFileKeyring keyring files. This issue only affected Ubuntu 11.10 and Ubuntu 12.04 LTS. (CVE-2012-4571)
It was discovered that Python Keyring created keyring files with insecure permissions. A local attacker could use this issue to access keyring files belonging to other users.
Affected
python-keyring on Ubuntu 12.10 ,
Ubuntu 12.04 LTS ,
Ubuntu 11.10
Severity
Classification
-
CVE CVE-2012-4571 -
CVSS Base Score: 2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities