oss-sec mailing list archives

CVE Request: gnome-keyring: improper caching of gpg password/passphrase


From: Huzaifa Sidhpurwala <huzaifas () redhat com>
Date: Thu, 09 Aug 2012 10:40:19 +0530

Hi All,

gnome-keyring does not obey the configuration asking it
to stop caching passphrases after a while.

More details and patches available at the following
references:

https://bugzilla.gnome.org/show_bug.cgi?id=681081
https://bugzilla.redhat.com/show_bug.cgi?id=845426

Upstream bug suggests that this is a regression from 3.3.x.
But it seems some older versions may also be affected.

Can a CVE id be please assigned to this issue?

Thanks!


-- 
Huzaifa Sidhpurwala / Red Hat Security Response Team


Current thread: