CVE-2018-19358 Affecting gnome-keyring package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-GNOMEKEYRING-1547442
  • published2 Dec 2018
  • disclosed18 Nov 2018

Introduced: 18 Nov 2018

CVE-2018-19358  (opens in a new tab)

How to fix?

There is no fixed version for Debian:12 gnome-keyring.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gnome-keyring package and not the gnome-keyring package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.