id: PYSEC-2019-181 details: Python keyring lib before 0.10 created keyring files with world-readable permissions. affected: - package: name: keyring ecosystem: PyPI purl: pkg:pypi/keyring ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: '0.10' versions: - '0.1' - '0.2' - '0.3' - '0.4' - '0.5' - 0.5.1 - 0.6.2 - '0.7' - 0.7.1 - '0.8' - 0.8.1 - '0.9' - 0.9.1 - 0.9.2 - 0.9.3 references: - type: WEB url: https://security-tracker.debian.org/tracker/CVE-2012-5577 - type: REPORT url: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5577 - type: WEB url: https://bitbucket.org/kang/python-keyring-lib/issue/67/set-go-rwx-on-keyring_passcfg - type: WEB url: http://www.openwall.com/lists/oss-security/2012/11/27/3 - type: WEB url: https://bitbucket.org/kang/python-keyring-lib/commits/049cd181470f1ee6c540e1d64acf1def7b1de0c1 - type: ADVISORY url: https://github.com/advisories/GHSA-p86x-652p-6385 aliases: - CVE-2012-5577 - GHSA-p86x-652p-6385 modified: '2021-08-27T03:22:05.629168Z' published: '2019-10-28T17:15:00Z'