Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take
advantage of a race condition when creating the Xauthority file to escalate
privileges (CVE-2020-28049).
- https://bugs.mageia.org/show_bug.cgi?id=27565
- https://lists.debian.org/debian-security-announce/2020/msg00190.html
- https://www.openwall.com/lists/oss-security/2020/11/04/2
- https://www.cve.org/CVERecord?id=CVE-2020-28049
- 7/core/sddm-0.18.1-3.1.mga7
Get the latest Linux and open source security news straight to your inbox.