Vulnerability Description
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gnome Keyring | < 3.27.2 |
| Canonical | Ubuntu Linux | 14.04 |
| Oracle | Zfs Storage Appliance Kit | 8.8 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1772919Issue TrackingPatchThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=781486Issue TrackingPatchVendor Advisory
- https://github.com/huntergregal/mimipenguinThird Party Advisory
- https://github.com/huntergregal/mimipenguin/tree/d95f1e08ce79783794f38433bbf7de5Third Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-keyring/issues/3Vendor Advisory
- https://gitlab.gnome.org/GNOME/gnome-keyring/tags/3.27.2Release NotesVendor Advisory
- https://usn.ubuntu.com/3894-1/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1772919Issue TrackingPatchThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=781486Issue TrackingPatchVendor Advisory
- https://github.com/huntergregal/mimipenguinThird Party Advisory
- https://github.com/huntergregal/mimipenguin/tree/d95f1e08ce79783794f38433bbf7de5Third Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-keyring/issues/3Vendor Advisory
- https://gitlab.gnome.org/GNOME/gnome-keyring/tags/3.27.2Release NotesVendor Advisory
- https://usn.ubuntu.com/3894-1/Third Party Advisory
FAQ
What is CVE-2018-20781?
CVE-2018-20781 is a vulnerability with a CVSS score of 7.8 (HIGH). In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
How severe is CVE-2018-20781?
CVE-2018-20781 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20781?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Gnome Keyring, Canonical Ubuntu Linux, Oracle Zfs Storage Appliance Kit.