LightDM Symlink Attack Local Privilege Escalation Vulnerability
BID:50506
CVE-2011-3349 |Info
LightDM Symlink Attack Local Privilege Escalation Vulnerability
| Bugtraq ID: | 50506 |
| Class: | Unknown |
| CVE: |
CVE-2011-3349 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 03 2011 12:00AM |
| Updated: | Nov 03 2011 12:00AM |
| Credit: | Sebastian Krahmer |
| Vulnerable: |
freedesktop.org Light Display Manager (LightDM) 0.9.2 |
| Not Vulnerable: |
freedesktop.org Light Display Manager (LightDM) 0.9.6 |
Discussion
LightDM Symlink Attack Local Privilege Escalation Vulnerability
Light Display Manager (LightDM) is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers.
Versions prior to LightDM 0.9.6 are vulnerable.
Light Display Manager (LightDM) is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers.
Versions prior to LightDM 0.9.6 are vulnerable.
Exploit / POC
LightDM Symlink Attack Local Privilege Escalation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
LightDM Symlink Attack Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
LightDM Symlink Attack Local Privilege Escalation Vulnerability
References:
References:
- Light Display Manager (LightDM) Homepage (Freedesktop.org)
- lightdm issues (Sebastian Krahmer)