GNOME Keyring CVE-2018-20781 Local Information Disclosure Vulnerability
BID:107453
Info
GNOME Keyring CVE-2018-20781 Local Information Disclosure Vulnerability
| Bugtraq ID: | 107453 |
| Class: | Design Error |
| CVE: |
CVE-2018-20781 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 12 2019 12:00AM |
| Updated: | Feb 12 2019 12:00AM |
| Credit: | Nicolas Iooss |
| Vulnerable: |
Ubuntu Ubuntu Linux 16.04 LTS Ubuntu Ubuntu Linux 14.04 LTS Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 GNOME gnome-keyring 3.20.1 GNOME gnome-keyring 3.6.0 GNOME gnome-keyring 3.4.1-4 GNOME gnome-keyring 3.4.1 GNOME gnome-keyring 3.4.0 GNOME gnome-keyring 3.4 GNOME gnome-keyring 3.2.0 GNOME gnome-keyring 3.2 GNOME gnome-keyring 3.0.0 GNOME gnome-keyring 2.30 |
| Not Vulnerable: |
GNOME gnome-keyring 3.27.2 |
Solution / Fix
GNOME Keyring CVE-2018-20781 Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNOME Keyring CVE-2018-20781 Local Information Disclosure Vulnerability
References:
References:
- GNOME Homepage (GNOME)
- gnome-keyring Homepage (GNOME)
- Bug 1677288 CVE-2018-20781 gnome-keyring (Redhat)
- Bug 781486 - Password is kept in process memory after pam_open_session (Gnome)
- CVE-2018-20781 (Redhat)
- pam-gnome-keyring.so reveals user�??s password credential as a plaintext form (Launchpad)
- pam-gnome-keyring.so reveals user�??s password credential as a plaintext form Edit (Gnome)
- USN-3894-1: GNOME Keyring vulnerability (Ubuntu)