First published: Fri Aug 03 2012(Updated: )
Julien Cristau <jcristau> reports: Package: gnome-keyring Version: 3.4.1-4 Severity: grave Tags: security Justification: user security hole At some point gnome-keyring seemed to obey the configuration asking it to stop caching passphrases after a while. It no longer does. $ gsettings list-recursively org.gnome.crypto.cache org.gnome.crypto.cache gpg-cache-authorize false org.gnome.crypto.cache gpg-cache-method 'idle' org.gnome.crypto.cache gpg-cache-ttl 600 Yet I'm never asked for the passphrase again. Cheers, Julien
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/gnome-keyring-3.4.1 | <3. | 3. |
GNOME gnome-keyring | =3.4.0 | |
GNOME gnome-keyring | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.