GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.
History

Wed, 18 Sep 2024 13:45:00 +0000

Type Values Removed Values Added
Metrics threat_severity

None

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-11-18T19:00:00Z

Updated: 2024-09-17T01:40:52.760Z

Reserved: 2018-11-18T00:00:00Z

Link: CVE-2018-19358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-18T19:29:00.297

Modified: 2024-08-05T12:15:23.783

Link: CVE-2018-19358

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-07-06T00:00:00Z

Links: CVE-2018-19358 - Bugzilla