CVE-2018-20781 log
| Source |
|
| Severity | Medium |
| Remote | No |
| Type | Information disclosure |
| Description | In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-932 | gnome-keyring | 3.20.1-1 | 3.27.2-1 | Medium | Fixed |
| References |
|---|
https://gitlab.gnome.org/GNOME/gnome-keyring/tags/3.27.2 https://gitlab.gnome.org/GNOME/gnome-keyring/issues/3 |