CVE-2018-20781: High severity Gnome GNOME Keyring vulnerability
Published Feb 12, 2019
·Updated
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
Affected Software
5 affected componentsFixes available
Gnome GNOME Keyring<3.27.2
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Oracle ZFS Storage Appliance Kit=8.8
debian/gnome-keyring
3.36.0-142.1-148.0-148.0-5
Remediation
Patch Available
Event History
Feb 12, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:00 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·07:09 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:10 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20781?
CVE-2018-20781 has a high severity as it exposes users' passwords in cleartext.
2
How do I fix CVE-2018-20781?
To fix CVE-2018-20781, update GNOME Keyring to version 3.28.0-1 or later.
3
Which versions of GNOME Keyring are affected by CVE-2018-20781?
CVE-2018-20781 affects GNOME Keyring versions before 3.27.2.
4
Is CVE-2018-20781 present in Ubuntu distributions?
Yes, CVE-2018-20781 is present in various Ubuntu distributions using affected GNOME Keyring versions.
5
What impact does CVE-2018-20781 have on system security?
CVE-2018-20781 potentially compromises user credentials, posing a significant risk to system security.