Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 11.10 USN-1262-1 Moderate: Light Display Manager Local Exploits

ubuntu
Calendar Grey November 15, 2011
Scroller Ubuntu
Numerous vulnerabilities found in the Light Display Manager necessitate urgent patches to safeguard system integrity on Ubuntu 11.10.
Several security issues were fixed in Light Display Manager.

Summary

Several security issues were fixed in Light Display Manager.

Software Description:

- lightdm: Display Manager

Details:

It was discovered that Light Display Manager incorrectly handled privileges

when reading .dmrc files. A local attacker could exploit this issue to read

arbitrary configuration files, bypassing intended permissions.

(CVE-2011-3153)

It was discovered that Light Display Manager incorrectly handled links when

adjusting permissions on .Xauthority files. A local attacker could exploit

this issue to access arbitrary files, and possibly obtain increased

privileges. In the default Ubuntu installation, this would be prevented

by the Yama link restrictions. (CVE-2011-4105)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  liblightdm-gobject-1-0          1.0.6-0ubuntu1.1
  liblightdm-qt-1-0               1.0.6-0ubuntu1.1
  lightdm                         1.0.6-0ubuntu1.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1262-1

CVE-2011-3153, CVE-2011-4105

Severity
important
Lowest
Low
Medium
High
Critical

November 15, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.