PT-2020-5744 · Sddm+2 · Sddm+2
Fabian Vogt
·
Published
2020-10-01
·
Updated
2024-10-23
·
CVE-2020-28049
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SDDM versions prior to 0.19.0
Description:
The issue is related to the incorrect start of the X server by SDDM, allowing local unprivileged users to create a connection to the X server without proper authentication for a short time period. This is caused by a race condition during Xauthority file creation, which can allow a local attacker to access X server display contents, intercept keystrokes, or access the clipboard.
Recommendations:
For SDDM versions prior to 0.19.0, update to version 0.19.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the X server to minimize the risk of exploitation. Avoid using SDDM until the issue is resolved. At the moment, there is information about a newer version that contains a fix for this vulnerability, which is SDDM 0.19.0.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Sddm
Suse