{"id":"UBUNTU-CVE-2008-7320","details":"** DISPUTED ** GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision.","modified":"2018-11-18T19:29:00Z","published":"2018-11-18T19:29:00Z","withdrawn":"2025-06-23T15:52:31Z","references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2008-7320"},{"type":"REPORT","url":"https://bugs.launchpad.net/ubuntu/+source/seahorse/+bug/189774"},{"type":"REPORT","url":"https://bugs.launchpad.net/ubuntu/+source/seahorse/+bug/189774/comments/13"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=551036"},{"type":"REPORT","url":"https://www.bountysource.com/issues/3849352-seahorse-shows-passwords-without-verification"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2008-7320"}],"affected":[{"package":{"name":"seahorse","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/seahorse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.16.0-1ubuntu1","3.18.0-2ubuntu1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7320.json"}},{"package":{"name":"seahorse","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/seahorse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.20.0-3.1","3.20.0-4","3.20.0-5"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7320.json"}},{"package":{"name":"seahorse","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/seahorse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.32.2-1","3.34-1","3.35.91-1","3.36-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7320.json"}},{"package":{"name":"seahorse","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/seahorse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["40.0-2","41.0-1","41.0-2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7320.json"}},{"package":{"name":"seahorse","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/seahorse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["43.0-1build1","43.0-3","43.0-3build1","43.0-3build2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2008/UBUNTU-CVE-2008-7320.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}