CVE Vulnerabilities

CVE-2018-19358

Published: Nov 18, 2018 | Modified: Aug 05, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
LOW

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the users session bus socket.

Affected Software

Name Vendor Start Version End Version
Gnome-keyring Gnome * 3.28.2 (including)
Gnome-keyring Ubuntu bionic *
Gnome-keyring Ubuntu cosmic *
Gnome-keyring Ubuntu disco *
Gnome-keyring Ubuntu eoan *
Gnome-keyring Ubuntu groovy *
Gnome-keyring Ubuntu hirsute *
Gnome-keyring Ubuntu impish *
Gnome-keyring Ubuntu kinetic *
Gnome-keyring Ubuntu lunar *
Gnome-keyring Ubuntu mantic *
Gnome-keyring Ubuntu trusty *
Gnome-keyring Ubuntu xenial *

References