CVE-2018-19358
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.
GNOME Keyring hasta la versión 3.28.2 permite que usuarios locales recuperen las credenciales de inicio de sesión mediante una llamada API Secret Service y la interfaz D-Bus si el keyring está desbloqueado. Este problema es similar a CVE-2008-7320. Una perspectiva es que esto ocurre debido a que los mecanismos de protección disponibles para D-Bus (relacionados con los elementos XML busconfig y policy) no se emplean.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-18 CVE Reserved
- 2018-11-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1652194#c8 | ||
https://gitlab.gnome.org/GNOME/gnome-keyring/-/issues/5#note_1876550 |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1780365 | 2024-09-17 | |
https://github.com/sungjungk/keyring_crack | 2024-09-17 | |
https://www.youtube.com/watch?v=Do4E9ZQaPck | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Gnome-keyring Search vendor "Gnome" for product "Gnome-keyring" | <= 3.28.2 Search vendor "Gnome" for product "Gnome-keyring" and version " <= 3.28.2" | - |
Affected
|