VulnerabilityModified
CVE-2008-7320
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked.
MEDIUM 6.8EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- gnome/seahorse
- Source
- cve@mitre.org
References
- https://bugs.launchpad.net/ubuntu/+source/seahorse/+bug/189774Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/seahorse/+bug/189774/comments/13Issue Tracking, Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=551036Issue Tracking, Vendor Advisory
- https://www.bountysource.com/issues/3849352-seahorse-shows-passwords-without-verificationThird Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/seahorse/+bug/189774Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/seahorse/+bug/189774/comments/13Issue Tracking, Third Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=551036Issue Tracking, Vendor Advisory
- https://www.bountysource.com/issues/3849352-seahorse-shows-passwords-without-verificationThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.