MGASA-2019-0111 - Updated gnome-keyring packages fix security vulnerability

Publication date: 14 Mar 2019
URL: https://advisories.mageia.org/MGASA-2019-0111.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-20781

It was discovered that GNOME Keyring incorrectly cleared out credentials
supplied to the PAM module. A local attacker could possibly use this
issue to discover login credentials (CVE-2018-20781).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24480
- https://ubuntu.com/security/notices/USN-3894-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20781

SRPMS:
- 6/core/gnome-keyring-3.20.0-1.1.mga6

Mageia 2019-0111: gnome-keyring security update

It was discovered that GNOME Keyring incorrectly cleared out credentials supplied to the PAM module

Summary

It was discovered that GNOME Keyring incorrectly cleared out credentials supplied to the PAM module. A local attacker could possibly use this issue to discover login credentials (CVE-2018-20781).

References

- https://bugs.mageia.org/show_bug.cgi?id=24480

- https://ubuntu.com/security/notices/USN-3894-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20781

Resolution

MGASA-2019-0111 - Updated gnome-keyring packages fix security vulnerability

SRPMS

- 6/core/gnome-keyring-3.20.0-1.1.mga6

Severity
Publication date: 14 Mar 2019
URL: https://advisories.mageia.org/MGASA-2019-0111.html
Type: security
CVE: CVE-2018-20781

Related News