PT-2020-5744 · Sddm+2 · Sddm+2

Fabian Vogt

·

Published

2020-10-01

·

Updated

2024-10-23

·

CVE-2020-28049

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SDDM versions prior to 0.19.0
Description: The issue is related to the incorrect start of the X server by SDDM, allowing local unprivileged users to create a connection to the X server without proper authentication for a short time period. This is caused by a race condition during Xauthority file creation, which can allow a local attacker to access X server display contents, intercept keystrokes, or access the clipboard.
Recommendations: For SDDM versions prior to 0.19.0, update to version 0.19.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the X server to minimize the risk of exploitation. Avoid using SDDM until the issue is resolved. At the moment, there is information about a newer version that contains a fix for this vulnerability, which is SDDM 0.19.0.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3209
ALT-PU-2020-3250
ALT-PU-2021-1734
ALT-PU-2024-14448
BDU:2021-01700
CVE-2020-28049
DLA-2436-1
DSA-4783-1
MGASA-2020-0412
OPENSUSE-SU-2020:1870-1
OPENSUSE-SU-2020:1899-1
OPENSUSE-SU-2020_1870-1
OPENSUSE-SU-2024:11376-1

Affected Products

Alt Linux
Sddm
Suse