Executive brief
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
Affected products
- PyPI keyring
Junglewise Threat Intelligence
CVE-2012-4571 · Severity: low · CVSS 3.1 · Published 2012-11-30
Technologies: keyring (PyPI). Vendors: PyPI.
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.