{"id":"CVE-2012-5578","aliases":["GHSA-8867-vpm3-g98g","PYSEC-2019-182"],"url":"https://o3.security/vulnerability/CVE-2012-5578","summary":"Incorrect Default Permissions in keyring","details":"Python keyring has insecure permissions on new databases allowing world-readable files to be created","published":"2019-11-25T13:15:11Z","modified":"2026-04-10T03:42:32.791861Z","cvss":{"score":6.2,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keyring","fixedVersion":"0.10"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2012/11/27/4"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/cve-2012-5578"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1031465"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5578"},{"type":"ADVISORY","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2012-5578"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2012-5578"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5578"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8867-vpm3-g98g"},{"type":"PACKAGE","url":"https://github.com/jaraco/keyring"},{"type":"WEB","url":"https://github.com/jaraco/keyring/blob/master/CHANGES.rst#010"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keyring/PYSEC-2019-182.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:42:32.791861Z"}}