Information disclosure in GNOME Keyring - CVE-2018-20781
Published: February 15, 2019 / Updated: September 19, 2022
Vulnerability details
The vulnerability allows a remote root privileged attacker to gain access to potentially sensitive information.
The vulnerability exists due to the LightDM daemon in the affected software stores user passwords in cleartext. A remote attacker can performa memory dump and retrieve login credentials, which can be used to conduct further attacks.
Affected software
gnome-keyring (Ubuntu package)
How to mitigate CVE-2018-20781
gnome-keyring (Ubuntu package) - addressed in versions 3.10.1-1ubuntu4.4, 3.18.3-0ubuntu2.1