CVE-2018-20781
12.02.2019, 17:29
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.Enginsight
Vendor | Product | Version |
---|---|---|
gnome | gnome_keyring | 𝑥 < 3.27.2 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 16.04 |
oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References