Bugzilla – Bug 1125261
VUL-1: CVE-2018-20781: gnome-keyring: user's cleartext password is kept in a session-child process
Last modified: 2020-06-29 06:37:56 UTC
CVE-2018-20781 In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20781 https://gitlab.gnome.org/GNOME/gnome-keyring/issues/3 https://bugzilla.gnome.org/show_bug.cgi?id=781486 https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1772919 https://gitlab.gnome.org/GNOME/gnome-keyring/tags/3.27.2
Codestreams affected: - SUSE:SLE-11-SP1:Update - SUSE:SLE-11-SP2:Update - SUSE:SLE-12:Update - SUSE:SLE-12-SP2:Update - SUSE:SLE-15:Update a fix is attached to the upstream ticket: https://bug781486.bugzilla-attachments.gnome.org/attachment.cgi?id=350049