PT-2018-2702 · Canonical+2 · Lightdm+3
Published
2018-03-18
·
Updated
2021-03-16
·
CVE-2018-20781
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GNOME Keyring versions prior to 3.27.2
Description
The issue is related to errors in managing registration data in the GNOME Keyring service for storing user names and passwords. Exploitation of this issue may allow an attacker to gain unauthorized access to protected information. Specifically, in versions before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon, potentially exposing the credential in cleartext.
Recommendations
For GNOME Keyring versions prior to 3.27.2, update to version 3.27.2 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information stored in GNOME Keyring until the update can be applied.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Gnome Keyring
Lightdm
Ubuntu