LWN.net Logo

lightdm: privilege escalation

Package(s):lightdm CVE #(s):CVE-2011-3153 CVE-2011-4105
Created:November 15, 2011 Updated:March 13, 2012
Description: From the Ubuntu advisory:

It was discovered that Light Display Manager incorrectly handled privileges when reading .dmrc files. A local attacker could exploit this issue to read arbitrary configuration files, bypassing intended permissions. (CVE-2011-3153)

It was discovered that Light Display Manager incorrectly handled links when adjusting permissions on .Xauthority files. A local attacker could exploit this issue to access arbitrary files, and possibly obtain increased privileges. In the default Ubuntu installation, this would be prevented by the Yama link restrictions. (CVE-2011-4105)

Alerts:
Ubuntu USN-1262-1 2011-11-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds