First published: Fri Dec 20 2019(Updated: )
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/gnome-keyring | 3.36.0-1 42.1-1 46.1-2 46.2-1 | |
GNOME Keyring | =3.2 | |
GNOME Keyring | =3.4 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6111 is classified as a medium severity vulnerability.
To fix CVE-2012-6111, update gnome-keyring to the latest version recommended for your operating system.
CVE-2012-6111 affects gnome-keyring versions 3.2, 3.4, and certain older versions.
No, other software using gnome-keyring functionalities may also be affected by CVE-2012-6111.
CVE-2012-6111 may allow unauthorized access to stored secrets if gnome_keyring_lock_all_sync is misused.