Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The package lxterminal before version 0.3.0-2 is vulnerable to access restriction bypass. . Arch Linux Security Advisory ASA-201706-25 ========================================= Severity: Medium Date : 2017-06-22 CVE-ID : CVE-2016-10369 Package : lxterminal Type : access restriction bypass Remote : No Link : https://security.archlinux.org/AVG-264 Summary ====== The package lxterminal before version 0.3.0-2 is vulnerable to access restriction bypass. Resolution ========= Upgrade to 0.3.0-2. # pacman -Syu "lxterminal> =0.3.0-2" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control). Impact ===== A local attacker might be able to cause a denial of service or bypass the terminal access control to gain privileges or access sensitive information. References ========= ;a=commitdiff;h=f99163c6ff8b2f57c5f37b1ce5d62cf7450d4648 https://unix.stackexchange.com/questions/333539/lxterminal-in-the-netstat-output/333578 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862098 https://security.archlinux.org/CVE-2016-10369 . Arch Linux Security Advisory ASA-202109-15 tackles a moderate severity privilege escalation vulnerability in gnome-terminal.. lxterminal Update, Access Control, Arch Linux Advisory. . Severity: Medium. LinuxSecurity.com Team
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-e9936d561b 2017-06-09 18:48:36.531419 --------------------------------------------------------------------------------Name : lxterminal Product : Fedora 26 Version : 0.3.0 Release : 3.fc26 URL : Summary : Desktop-independent VTE-based terminal emulator Description : LXterminal is a VTE-based terminal emulator with support for multiple tabs. It is completely desktop-independent and does not have any unnecessary dependencies. In order to reduce memory usage and increase the performance all instances of the terminal are sharing a single process. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creationin get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lxterminal' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3f2d5790d2 2017-05-30 15:08:36.562803 --------------------------------------------------------------------------------Name : lxterminal Product : Fedora 24 Version : 0.3.0 Release : 3.fc24 URL : Summary : Desktop-independent VTE-based terminal emulator Description : LXterminal is a VTE-based terminal emulator with support for multiple tabs. It is completely desktop-independent and does not have any unnecessary dependencies. In order to reduce memory usage and increase the performance all instances of the terminal are sharing a single process. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creationin get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lxterminal' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3f2d5790d2 2017-05-30 15:08:36.562803 --------------------------------------------------------------------------------Name : pcmanfm Product : Fedora 24 Version : 1.2.5 Release : 2.fc24 URL : Summary : Extremly fast and lightweight file manager Description : PCMan File Manager is an extremly fast and lightweight file manager which features tabbed browsing and user-friendly interface. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcmanfm' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3f2d5790d2 2017-05-30 15:08:36.562803 --------------------------------------------------------------------------------Name : menu-cache Product : Fedora 24 Version : 1.0.2 Release : 4.D20170514git56f6668459.fc24 URL : Summary : Caching mechanism for freedesktop.org compliant menus Description : Menu-cache is a caching mechanism for freedesktop.org compliant menus to speed up parsing of the menu entries. It is currently used by some of components of the LXDE desktop environment such as LXPanel or LXLauncher. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade menu-cache' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-6950ea5d05 2017-05-17 03:56:11.755807 --------------------------------------------------------------------------------Name : lxterminal Product : Fedora 25 Version : 0.3.0 Release : 3.fc25 URL : Summary : Desktop-independent VTE-based terminal emulator Description : LXterminal is a VTE-based terminal emulator with support for multiple tabs. It is completely desktop-independent and does not have any unnecessary dependencies. In order to reduce memory usage and increase the performance all instances of the terminal are sharing a single process. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creationin get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lxterminal' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-6950ea5d05 2017-05-17 03:56:11.755807 --------------------------------------------------------------------------------Name : pcmanfm Product : Fedora 25 Version : 1.2.5 Release : 2.fc25 URL : Summary : Extremly fast and lightweight file manager Description : PCMan File Manager is an extremly fast and lightweight file manager which features tabbed browsing and user-friendly interface. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcmanfm' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that there was a local denial of service vulnerability in lxterminal, the terminal emulator for the LXDE desktop environment. This was caused by an insecure use of temporary files for a socket file. . Hash: SHA256 Package : lxterminal Version : 0.1.11-4+deb7u1 CVE ID : CVE-2016-10369 Debian Bug : #862098 It was discovered that there was a local denial of service vulnerability in lxterminal, the terminal emulator for the LXDE desktop environment. This was caused by an insecure use of temporary files for a socket file. For Debian 7 "Wheezy", this issue has been fixed in lxterminal version 0.1.11-4+deb7u1. We recommend that you upgrade your lxterminal packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.