- lightdm-1.24.0 - Disable guest login as system default preset (CVE-2017-8900) - Modernize spec-file. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-159a1060f6 2017-09-30 05:57:53.214535 --------------------------------------------------------------------------------Name : lightdm Product : Fedora 27 Version : 1.24.0 Release : 1.fc27 URL : https://launchpad.net/lightdm/1.24 Summary : A cross-desktop Display Manager Description : Lightdm is a display manager that: * Is cross-desktop - supports different desktops * Supports different display technologies * Is lightweight - low memory usage and fast performance --------------------------------------------------------------------------------Update Information: - lightdm-1.24.0 - Disable guest login as system default preset (CVE-2017-8900) - Modernize spec-file --------------------------------------------------------------------------------References: [ 1 ] Bug #1488270 - lightdm-1.24.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1488270 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lightdm' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
LightDM could allow unintended access to files.. =========================================================================Ubuntu Security Notice USN-3285-1 May 12, 2017 lightdm vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 Summary: LightDM could allow unintended access to files. Software Description: - lightdm: Display Manager Details: Tyler Hicks discovered that LightDM did not confine the user session for guest users. An attacker with physical access could use this issue to access files and other resources that they should not be able to access. In the default installation, this includes files in the home directories of other users on the system. This update fixes the issue by disabling the guest session. It may be re-enabled in a future update. Please see the bug referenced below for instructions on how to manually re-enable the guest session. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: lightdm 1.22.0-0ubuntu2.1 Ubuntu 16.10: lightdm 1.19.5-0ubuntu1.2 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3285-1 CVE-2017-8900, https://bugs.launchpad.net/ubuntu/+source/lightdm/+bug/1663157 Package Information: https://launchpad.net/ubuntu/+source/lightdm/1.22.0-0ubuntu2.1 https://launchpad.net/ubuntu/+source/lightdm/1.19.5-0ubuntu1.2 . Ubuntu Security Notice USN-3285-2 deals with vulnerabilities in LightDM that allow unauthorized file access.. LightDM Vulnerability, Ubuntu Security Notice, Access Control Issue. . Severity: Important. LinuxSecurity.com Team
Light Display Manager could be made to expose sensitive information locally.. =========================================================================Ubuntu Security Notice USN-2012-1 November 06, 2013 lightdm vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 Summary: Light Display Manager could be made to expose sensitive information locally. Software Description: - lightdm: Display Manager Details: Christian Prim discovered that Light Display Manager incorrectly applied the AppArmor security profile when the Guest account is used. A local attacker could use this issue to possibly gain access to sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: lightdm 1.8.4-0ubuntu1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2012-1 CVE-2013-4459 Package Information: https://launchpad.net/ubuntu/+source/lightdm/1.8.4-0ubuntu1 . An issue within the Screen Control Interface might leak critical data locally in Ubuntu 13.10.. Light Display Manager, Ubuntu Security Advisory, Local Threats. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.