PT-2018-14941 · Gnome+2 · Gnome Keyring+2

CVE-2018-19358

·

Publicado

2018-11-18

·

Atualizado

2024-08-05

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNOME Keyring versions prior to 3.28.2
Description The issue allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked. This occurs because available D-Bus protection mechanisms are not used. The vendor disputes this issue, citing that untrusted applications must not be allowed to access the user's session bus socket.
Recommendations For GNOME Keyring versions prior to 3.28.2, consider restricting access to the D-Bus interface to minimize the risk of exploitation. As a temporary workaround, restrict the use of the Secret Service API call until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2019-1457
CVE-2018-19358

Produtos afetados

Alt Linux
Debian
Gnome Keyring