GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnome-keyring | Jul 30, 2024 | Oct 22, 2012 |
| Suse | — | Upgrade gnome-keyring-pamUpgrade gnome-keyringUpgrade gnome-keyring-langUpgrade gnome-keyring-32bitUpgrade gnome-keyring-pam-32bitUpgrade libgck-modules-gnome-keyring | Dec 12, 2013 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub