PT-2015-4920 · Kde+1 · Sddm+1
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sddm versions prior to 0.13.0
Description
The issue is related to the daemon/Greeter.cpp in sddm, where it does not properly disable the KDE crash handler. This allows local users to gain privileges by crashing a greeter when using certain themes. An example of such a theme is the plasma-workspace breeze theme.
Recommendations
For versions prior to 0.13.0, update to version 0.13.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of themes that may trigger the crash handler, such as the plasma-workspace breeze theme, until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Sddm