Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
202

openSUSE: 2020:1899-1 Moderate: sddm Access Control Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for sddm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1899-1 Rating: moderate References: #1177201 Cross-References: CVE-2020-28049 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sddm fixes the following issue: - Fix X not having access control on startup (boo#1177201, CVE-2020-28049). This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-1899=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): sddm-0.18.0-bp152.5.3.1 sddm-branding-SLE-0.18.0-bp152.5.3.1 sddm-branding-openSUSE-0.18.0-bp152.5.3.1 sddm-branding-upstream-0.18.0-bp152.5.3.1 References: https://www.suse.com/security/cve/CVE-2020-28049.html https://bugzilla.suse.com/1177201 _______________________________________________ openSUSE Security Announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe, email This email address is being protected from spambots. You need JavaScript enabled to view it. List Netiquette: https://en.opensuse.org/openSUSE:Mailing_list_netiquette List Archives: . A new update is now ready for openSUSE's sddm, aimed at mitigating access control vulnerabilities. Further information is included within.. openSUSE Security, SDDM Update, Access Control Issue, Linux Patch. . LinuxSecurity.com Team

Calendar 2 Nov 11, 2020 OpenSUSE
198

Arch Linux: ASA-202011-8 Medium: sddm Privilege Escalation Alert

The package sddm before version 0.19.0-1 is vulnerable to privilege escalation. . Arch Linux Security Advisory ASA-202011-8 ======================================== Severity: Medium Date : 2020-11-10 CVE-ID : CVE-2020-28049 Package : sddm Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-1266 Summary ====== The package sddm before version 0.19.0-1 is vulnerable to privilege escalation. Resolution ========= Upgrade to 0.19.0-1. # pacman -Syu "sddm> =0.19.0-1" The problem has been fixed upstream in version 0.19.0. Workaround ========= None. Description ========== A local privilege escalation has been discovered in the sddm display manager < 0.19.0. If the auth file is empty, X allows any local application (= any user on the system) to connect. This is currently the case until X wrote the display number to sddm and sddm used that to write the entry into the file. Impact ===== A local user might be able to escalate privileges. References ========= https://www.openwall.com/lists/oss-security/2020/11/04/2 https://github.com/sddm/sddm/commit/be202f533ab98a684c6a007e8d5b4357846bc222 https://security.archlinux.org/CVE-2020-28049 . The Arch Linux Security Advisory ASA-2023-5 pertains to a moderate severity vulnerability in sddm that allows for privilege escalation, requiring timely patches.. Arch Linux, sddm, privilege escalation, security advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Nov 10, 2020 Medium ArchLinux
203

Mageia: 2020-0412 Critical: sddm Race Condition Exploit

Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049). References: . MGASA-2020-0412 - Updated sddm package fixes a security vulnerability Publication date: 10 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0412.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-28049 Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049). References: - https://bugs.mageia.org/show_bug.cgi?id=27565 - https://lists.debian.org/debian-security-announce/2020/msg00190.html - https://www.openwall.com/lists/oss-security/2020/11/04/2 - https://www.cve.org/CVERecord?id=CVE-2020-28049 SRPMS: - 7/core/sddm-0.18.1-3.1.mga7 . The new version of the sddm package addresses a critical security vulnerability in Mageia, improving overall system safety.. sddm security update,mageia privilege escalation,local attacker flaw,sddm race condition. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 10, 2020 Critical Mageia
202

openSUSE Leap 15.2: openSUSE-SU-2020:1870-1 Moderate: sddm Access Control

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for sddm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1870-1 Rating: moderate References: #1177201 Cross-References: CVE-2020-28049 Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for sddm fixes the following issue: - Fix X not having access control on startup (boo#1177201, CVE-2020-28049). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1870=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1870=1 Package List: - openSUSE Leap 15.2 (x86_64): sddm-0.18.0-lp152.5.3.1 sddm-branding-openSUSE-0.18.0-lp152.5.3.1 sddm-branding-upstream-0.18.0-lp152.5.3.1 sddm-debuginfo-0.18.0-lp152.5.3.1 sddm-debugsource-0.18.0-lp152.5.3.1 - openSUSE Leap 15.1 (x86_64): sddm-0.18.0-lp151.3.6.1 sddm-branding-openSUSE-0.18.0-lp151.3.6.1 sddm-branding-upstream-0.18.0-lp151.3.6.1 sddm-debuginfo-0.18.0-lp151.3.6.1 sddm-debugsource-0.18.0-lp151.3.6.1 References: https://www.suse.com/security/cve/CVE-2020-28049.html https://bugzilla.suse.com/1177201 -- . A recent update for openSUSE addressing sddm resolves a significant security vulnerability linked to CVE-2021-12345.. openSUSE Update, sddm Security, Access Control Issue, Security Patch, Moderate Rating. . LinuxSecurity.com Team

Calendar 2 Nov 07, 2020 OpenSUSE
87

Debian: DSA-4783-1 Local Attack Risks in sddm Mitigated

Fabian Vogt discovered a flaw in sddm, a modern display manager for X11. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4783-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 05, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sddm CVE ID : CVE-2020-28049 Debian Bug : 973748 Fabian Vogt discovered a flaw in sddm, a modern display manager for X11. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges. For the stable distribution (buster), this problem has been fixed in version 0.18.0-1+deb10u1. We recommend that you upgrade your sddm packages. For the detailed security status of sddm please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sddm Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu security notice USN-4783-1 highlights a vulnerability in lightdm permitting local privilege escalation via timing issues.. Debian Security, sddm Flaw, X11 Display Manager, Privilege Escalation, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 05, 2020 Important Debian
202

openSUSE Leap 15.0: 2018:2310-1 Moderate: sddm Authentication Issue

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for sddm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2310-1 Rating: moderate References: #1099908 #1101450 Cross-References: CVE-2018-14345 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for sddm fixes the following issues: The following security vulnerability was addressed: - CVE-2018-14345: Fixed the authentication, which did not check the password for users with an already existing session and allowed any user with access to the system bus to unlock any graphical session. (boo#1101450) The following other bugs were addressed: - Fallback to embedded theme, if none is set - Corrected section name for Wayland - Removed patch, which is no longer needed, because bug in libxcb was fixed in the meanwhile (boo#1099908) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-862=1 Package List: - openSUSE Leap 15.0 (x86_64): sddm-0.17.0-lp150.9.3.1 sddm-branding-openSUSE-0.17.0-lp150.9.3.1 sddm-branding-upstream-0.17.0-lp150.9.3.1 sddm-debuginfo-0.17.0-lp150.9.3.1 sddm-debugsource-0.17.0-lp150.9.3.1 References: https://www.suse.com/security/cve/CVE-2018-14345.html https://bugzilla.suse.com/1099908 https://bugzilla.suse.com/1101450 -- . openSUSE Security Update: Security update for sddm _________________________________________________. update, solves, vulnerability, errata,opensuse, security, updat. . LinuxSecurity.com Team

Calendar 2 Aug 13, 2018 OpenSUSE
89

Fedora 22: 2015:9f996ea146 Critical: sddm Access Control Issue

sddm-0.12.0-5.fc22 - Security fix for CVE-2015-0856 ---- Refresh to latest stable upstream release, see: https://github.com/sddm/sddm/wiki/ -Release-Announcement. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9f996ea146 2015-11-12 21:42:38.336761 -------------------------------------------------------------------------------- Name : sddm Product : Fedora 22 Version : 0.12.0 Release : 5.fc22 URL : https://github.com/sddm/sddm Summary : QML based X11 desktop manager Description : SDDM is a modern display manager for X11 aiming to be fast, simple and beautiful. It uses modern technologies like QtQuick, which in turn gives the designer the ability to create smooth, animated user interfaces. -------------------------------------------------------------------------------- Update Information: sddm-0.12.0-5.fc22 - Security fix for CVE-2015-0856 ---- Refresh to latest stable upstream release, see: https://github.com/sddm/sddm/wiki/ -Release-Announcement -------------------------------------------------------------------------------- References: [ 1 ] Bug #1271992 - CVE-2015-0856 sddm: Access to the KDE crash handler https://bugzilla.redhat.com/show_bug.cgi?id=1271992 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update sddm' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Security noticefor Fedora 22: sddm patch resolving permission control vulnerabilities linked to CVE-2015-0856 flaw.. Fedora 22 Security Update,sddm,Access Control,Qt Desktop Manager. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 13, 2015 Critical Fedora
89

Fedora 23: Critical SDDM Access Issue Fix - CVE-2015-0856

sddm-0.12.0-5.fc23 - Security fix for CVE-2015-0856. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-b15b90eeaa 2015-10-31 16:04:40.594018 -------------------------------------------------------------------------------- Name : sddm Product : Fedora 23 Version : 0.12.0 Release : 5.fc23 URL : https://github.com/sddm/sddm Summary : QML based X11 desktop manager Description : SDDM is a modern display manager for X11 aiming to be fast, simple and beautiful. It uses modern technologies like QtQuick, which in turn gives the designer the ability to create smooth, animated user interfaces. -------------------------------------------------------------------------------- Update Information: sddm-0.12.0-5.fc23 - Security fix for CVE-2015-0856 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1271992 - CVE-2015-0856 sddm: Access to the KDE crash handler https://bugzilla.redhat.com/show_bug.cgi?id=1271992 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update sddm' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Uncover vital sddm security patch for Fedora resolving entry problem and enhancing overall system reliability.. Fedora sddm security update, Linux desktop manager security, critical sddm fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 31, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here