CVE-2012-5577: High severity Python Keyring vulnerability
Published Oct 28, 2019
·Updated
Python keyring lib before 0.10 created keyring files with world-readable permissions.
Affected Software
4 affected componentsFixes available
pip/keyring<0.10
0.10
Python Keyring<0.10
Debian Debian Linux=7.0
debian/python-keyring
22.0.1-123.9.3-225.6.0-225.7.0-1
Remediation
Event History
Oct 28, 2019
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionWeakness
Mar 11, 2020
Advisory Published
via GitHub·09:36 PM
Feb 18, 2026
Data Sourced
via Debian·02:27 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-5577?
CVE-2012-5577 is classified as a medium severity vulnerability due to its potential to expose sensitive keyring information.
2
How do I fix CVE-2012-5577?
To fix CVE-2012-5577, upgrade the keyring library to version 0.10 or later.
3
Which versions of keyring are affected by CVE-2012-5577?
CVE-2012-5577 affects all versions of the keyring library prior to 0.10.
4
What are the risks of using an affected version of keyring for CVE-2012-5577?
Using an affected version of keyring can lead to unauthorized access to stored credentials due to insecure file permissions.
5
Is CVE-2012-5577 specific to a certain operating system?
CVE-2012-5577 impacts the keyring library regardless of the operating system but is particularly noted in versions used in Debian systems.