Vulnerability Database
Blog
FAQ
Docs
PYSEC-2019-181
See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/keyring/PYSEC-2019-181.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2019-181
Aliases
CVE-2012-5577
GHSA-p86x-652p-6385
Published
2019-10-28T17:15:00Z
Modified
2023-11-01T04:44:53.081226Z
Summary
[none]
Details
Python keyring lib before 0.10 created keyring files with world-readable permissions.
References
https://security-tracker.debian.org/tracker/CVE-2012-5577
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5577
https://bitbucket.org/kang/python-keyring-lib/issue/67/set-go-rwx-on-keyring_passcfg
http://www.openwall.com/lists/oss-security/2012/11/27/3
https://bitbucket.org/kang/python-keyring-lib/commits/049cd181470f1ee6c540e1d64acf1def7b1de0c1
https://github.com/advisories/GHSA-p86x-652p-6385
Affected packages
PyPI
/
keyring
Package
Name
keyring
View open source insights on deps.dev
Purl
pkg:pypi/keyring
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0.10
Affected versions
0.*
0.1
0.2
0.3
0.4
0.5
0.5.1
0.6.2
0.7
0.7.1
0.8
0.8.1
0.9
0.9.1
0.9.2
0.9.3
PYSEC-2019-181 - OSV