4.4
CVSSv2

CVE-2012-3466

Published: 22/10/2012 Updated: 05/12/2013
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

GNOME gnome-keyring 3.4.0 up to and including 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows malicious users to have an unspecified impact via unknown attack vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome-keyring 3.4.1

gnome gnome-keyring 3.4.0

Vendor Advisories

Debian Bug report logs - #683655 gnome-keyring: gpg passphrase cached forever Package: gnome-keyring; Maintainer for gnome-keyring is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for gnome-keyring is src:gnome-keyring (PTS, buildd, popcon) Reported by: Julien Cristau <jcristau@debianor ...