CVE-2018-20781

EUVD-2018-13324
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
gnomegnome_keyring
𝑥
< 3.27.2
canonicalubuntu_linux
14.04
canonicalubuntu_linux
16.04
oraclezfs_storage_appliance_kit
8.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnome-keyring
bookworm
42.1-1
fixed
bullseye
3.36.0-1
fixed
sid
46.2-1
fixed
trixie
46.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-keyring
bionic
not-affected
cosmic
not-affected
trusty
Fixed 3.10.1-1ubuntu4.4
released
xenial
Fixed 3.18.3-0ubuntu2.1
released