Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 23: lxdm Update Critical Local User X Connection Risk

fedora
Calendar Grey November 1, 2015
Dist Fedora Esm H88
The LXDM software update enhances the security of Fedora 23 by preventing unauthorized local user access to X server connections.
A bug is reported that session opened via LXDM allows any local users to connect X

Summary

LXDM is the future display manager of LXDE, the Lightweight X11 Desktop

environment. It is designed as a lightweight alternative to replace GDM or

KDM in LXDE distros. It's still in very early stage of development.

Update Information:

A bug is reported that session opened via LXDM allows any local users to connect X. This new package should fix this issue.

Change Log

References


[ 1 ] Bug #1268900 - lxdm: X server started without -auth, exposing it to connections form any local user https://bugzilla.redhat.com/show_bug.cgi?id=1268900

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update lxdm' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: lxdm
Product: Fedora 23
Version: 0.5.1
Release: 7.D20151007gite8f38708.fc23
URL:
Summary: Lightweight X11 Display Manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here