Python keyring '_relocate_file()' Function Insecure File Permissions Vulnerability
BID:56578
Info
Python keyring '_relocate_file()' Function Insecure File Permissions Vulnerability
| Bugtraq ID: | 56578 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 16 2012 12:00AM |
| Updated: | Nov 16 2012 12:00AM |
| Credit: | Jamie Strandboge |
| Vulnerable: |
Python Software Foundation keyring 0.9.1 Python Software Foundation keyring 0.8.1 Python Software Foundation keyring 0.9 |
| Not Vulnerable: |
Python Software Foundation keyring 0.10 |
Discussion
Python keyring '_relocate_file()' Function Insecure File Permissions Vulnerability
The Python keyring is prone to an insecure file-permission vulnerability.
An attacker can exploit this issue to obtain sensitive information. This may aid in further attacks.
The Python keyring is prone to an insecure file-permission vulnerability.
An attacker can exploit this issue to obtain sensitive information. This may aid in further attacks.
Exploit / POC
Python keyring '_relocate_file()' Function Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
Python keyring '_relocate_file()' Function Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Python keyring '_relocate_file()' Function Insecure File Permissions Vulnerability
References:
References:
- ~/crypted_pass.cfg created with insecure permissions (Ubuntu)
- COMMIT (Jason R. Coombs)
- Issue: Rset go-rwx on keyring_pass.cfg (Daniel Holth)
- Python keyring HomePage (Python Software Foundation)