Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2020-0412 Critical: sddm Race Condition Exploit

mageia
Calendar Grey November 10, 2020
Dist Mageia Esm H88
The new version of the sddm package addresses a critical security vulnerability in Mageia, improving overall system safety.
Fabian Vogt discovered a flaw in sddm before 0.19.0

Summary

Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049).

References

- https://bugs.mageia.org/show_bug.cgi?id=27565

- https://lists.debian.org/debian-security-announce/2020/msg00190.html

- https://www.openwall.com/lists/oss-security/2020/11/04/2

- https://www.cve.org/CVERecord?id=CVE-2020-28049

Resolution

SRPMS

- 7/core/sddm-0.18.1-3.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0412.html
Type: security
CVE: CVE-2020-28049

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here