---
title: "CVE-2012-6111\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-6111?format=md
keywords: index, follow
---

# CVE-2012-6111

Publication date 20 December 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2012-6111?format=md#impact-score)

Toggle side navigation

## Description

gnome-keyring does not discard stored secrets when using
gnome\_keyring\_lock\_all\_sync function

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-6111?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| gnome-keyring | 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Not in release |
| 13.10 saucy | Ignored end of life |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

In hardy, gnome\_keyring\_lock\_all\_sync() was in the gnome-keyring
package, and works as expected.
In 2.30+ in Lucid+, gnome\_keyring\_lock\_all\_sync() is in
libgnome-keyring and sends a LockService DBus call to
gnome-keyring. This call isn't implemented in lucid+
Nothing in the archive in Oneiric+ actually uses
gnome\_keyring\_lock\_all\_sync(), so this is low.
In Lucid, gnome-power-manager calls this before suspend and
hibernation with the intention of locking the keyring.
Fixing this in Lucid would result in the user likely having to
retype their keyring password when coming out of suspend and
hibernation, which is an intrusive change this late in Lucid's
lifecycle.
Setting this issue as priority low for the reasons above.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6111)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-6111)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-6111)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-6111)

### Other references

* <http://www.openwall.com/lists/oss-security/2013/01/11/5>
* <https://www.cve.org/CVERecord?id=CVE-2012-6111>
