« Volver al listado

CVE-2012-3466

Estado: ModificadaMedia (4.4)—

GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-3466",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.4,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-22T23:55:06.057",
  "references": [
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683655",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://git.gnome.org/browse/gnome-keyring/commit/?id=51606f299e5ee9d48096db0a5957efe26cbf7cc3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://git.gnome.org/browse/gnome-keyring/commit/?id=5dff623470b859e332dbe12afb0dc57b292832d2",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-09/msg00037.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:084",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/09/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/09/2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=681081",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=845426",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683655",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://git.gnome.org/browse/gnome-keyring/commit/?id=51606f299e5ee9d48096db0a5957efe26cbf7cc3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://git.gnome.org/browse/gnome-keyring/commit/?id=5dff623470b859e332dbe12afb0dc57b292832d2",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-09/msg00037.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:084",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/09/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/09/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.gnome.org/show_bug.cgi?id=681081",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=845426",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to \"idle\" or \"timeout,\" does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors."
    },
    {
      "lang": "es",
      "value": "GNOME gnome-keyring v3.4.0 hasta v3.4.1, cuando gpg-cache-method se establece en \"idle\" o \"timeout\", no limita correctamente la cantidad de tiempo que una contraseña se almacena en caché, lo que permite a los atacantes tener un impacto no especificado a través de vectores de ataque desconocidos."
    }
  ],
  "lastModified": "2026-06-16T23:43:16.927",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:gnome-keyring:3.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DF68164-EEEE-4499-AEF5-F8FE449F47A5"
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-keyring:3.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0D7C15C-901D-432C-A233-349DBCC40816"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}