High severity7.8NVD Advisory· Published Feb 12, 2019· Updated Jun 17, 2026
CVE-2018-20781
CVE-2018-20781
Description
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<3.27.2+ 1 more
- (no CPE)range: <3.27.2
- (no CPE)range: <3.27.2
- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
Patches
Vulnerability mechanics
References
7- bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1772919nvdIssue TrackingPatchThird Party Advisory
- bugzilla.gnome.org/show_bug.cginvdIssue TrackingPatchVendor Advisory
- github.com/huntergregal/mimipenguin/tree/d95f1e08ce79783794f38433bbf7de5abd9792danvdThird Party Advisory
- gitlab.gnome.org/GNOME/gnome-keyring/issues/3nvdVendor Advisory
- gitlab.gnome.org/GNOME/gnome-keyring/tags/3.27.2nvdRelease NotesVendor Advisory
- usn.ubuntu.com/3894-1/nvdThird Party Advisory
- www.oracle.com/security-alerts/cpujan2021.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.