SB2018112113 - Information disclosure in GNOME Keyring
Published: November 21, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2018-19358)
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to improper use of D-Bus protection mechanisms. A local attacker can execute a program that uses the D-Bus interface and a Secret Service API call to submit malicious input to retrieve login credentials, which could be used to conduct further attacks.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.