GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision
Name | Vendor | Start Version | End Version |
---|---|---|---|
Seahorse | Gnome | * | 3.30 (including) |
Seahorse | Ubuntu | bionic | * |
Seahorse | Ubuntu | cosmic | * |
Seahorse | Ubuntu | disco | * |
Seahorse | Ubuntu | eoan | * |
Seahorse | Ubuntu | groovy | * |
Seahorse | Ubuntu | hirsute | * |
Seahorse | Ubuntu | impish | * |
Seahorse | Ubuntu | kinetic | * |
Seahorse | Ubuntu | lunar | * |
Seahorse | Ubuntu | mantic | * |
Seahorse | Ubuntu | trusty | * |
Seahorse | Ubuntu | xenial | * |