CVE-2012-5578: Medium severity Python Keyring vulnerability
Published Nov 25, 2019
·Updated
Python keyring has insecure permissions on new databases allowing world-readable files to be created
Other sources
Python keyring has insecure permissions on new databases, allowing world-readable files to be created.
— GitHub
Affected Software
3 affected componentsFixes available
pip/keyring<0.10
0.10
Python Keyring<=0.10
debian/python-keyring
22.0.1-123.9.3-225.6.0-225.7.0-1
Remediation
Event History
Nov 25, 2019
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionWeakness
Mar 10, 2020
Advisory Published
via GitHub·08:56 PM
Feb 18, 2026
Data Sourced
via Debian·02:27 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-5578?
The severity of CVE-2012-5578 is classified as medium due to the potential for unauthorized file access.
2
How do I fix CVE-2012-5578?
To fix CVE-2012-5578, upgrade Python keyring to version 22.0.1-1, 23.9.3-2, or 25.4.1-1.
3
What are the affected versions of Python keyring for CVE-2012-5578?
Versions of Python keyring up to and including 0.10 are affected by CVE-2012-5578.
4
What type of vulnerability is CVE-2012-5578?
CVE-2012-5578 is a permissions vulnerability that allows the creation of world-readable files.
5
Can CVE-2012-5578 affect other software besides Python?
CVE-2012-5578 specifically affects the Python keyring package and is not related to other software.