PT-2015-4920 · Kde+1 · Sddm+1
David Edmundson
·
Published
2015-11-05
·
Updated
2024-06-15
·
CVE-2015-0856
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sddm versions prior to 0.13.0
Description
The issue is related to the daemon/Greeter.cpp in sddm, where it does not properly disable the KDE crash handler. This allows local users to gain privileges by crashing a greeter when using certain themes. An example of such a theme is the plasma-workspace breeze theme.
Recommendations
For versions prior to 0.13.0, update to version 0.13.0 or later to resolve the issue. As a temporary workaround, consider avoiding the use of themes that may trigger the crash handler, such as the plasma-workspace breeze theme, until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Sddm