Upstream information

CVE-2011-3349 at MITRE

Description

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.2
Vector AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
CVSS v3 Scores
  National Vulnerability Database
Base Score 7.8
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
CVSSv3 Version 3.1
SUSE Bugzilla entry: 708205 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 15.0
  • liblightdm-gobject-1-0 >= 1.24.1-lp150.1.1
  • lightdm >= 1.24.1-lp150.1.1
  • lightdm-lang >= 1.24.1-lp150.1.1
Patchnames:
openSUSE Leap 15.0 GA liblightdm-gobject-1-0-1.24.1-lp150.1.1
openSUSE Tumbleweed
  • liblightdm-gobject-1-0 >= 1.21.1-1.1
  • liblightdm-qt-3-0 >= 1.21.1-1.1
  • liblightdm-qt5-3-0 >= 1.21.1-1.1
  • lightdm >= 1.21.1-1.1
  • lightdm-gobject-devel >= 1.21.1-1.1
  • lightdm-lang >= 1.21.1-1.1
  • lightdm-qt-devel >= 1.21.1-1.1
  • lightdm-qt5-devel >= 1.21.1-1.1
  • typelib-1_0-LightDM-1 >= 1.21.1-1.1
Patchnames:
openSUSE-Tumbleweed-2024-10033


SUSE Timeline for this CVE

CVE page created: Tue Jul 9 19:15:45 2013
CVE page last modified: Tue Sep 17 11:13:21 2024