vulnerability

Ubuntu: USN-3894-1 (CVE-2018-20781): GNOME Keyring vulnerability

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
Published
02/12/2019
Added
03/06/2019
Modified
11/07/2024

Description

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.

Solution(s)

ubuntu-upgrade-gnome-keyringubuntu-upgrade-libpam-gnome-keyring
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.