LightDM 'xsession_setup()' Symlink Attack Local Privilege Escalation Vulnerability
BID:50511
Info
LightDM 'xsession_setup()' Symlink Attack Local Privilege Escalation Vulnerability
| Bugtraq ID: | 50511 |
| Class: | Design Error |
| CVE: |
CVE-2011-4105 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 03 2011 12:00AM |
| Updated: | Feb 21 2012 11:40PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 freedesktop.org LightDM 1.0.5 freedesktop.org LightDM 1.0.4 |
| Not Vulnerable: |
freedesktop.org LightDM 1.0.6 |
Discussion
LightDM 'xsession_setup()' Symlink Attack Local Privilege Escalation Vulnerability
Light Display Manager (LightDM) is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers.
LightDM 1.0.4 and 1.0.5 are vulnerable; other versions may also be affected.
Light Display Manager (LightDM) is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to gain elevated privileges on affected computers.
LightDM 1.0.4 and 1.0.5 are vulnerable; other versions may also be affected.
Exploit / POC
LightDM 'xsession_setup()' Symlink Attack Local Privilege Escalation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
LightDM 'xsession_setup()' Symlink Attack Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
LightDM 'xsession_setup()' Symlink Attack Local Privilege Escalation Vulnerability
References:
References:
- Light Display Manager (LightDM) Homepage (Freedesktop.org)
- Version 1.0.6 released (LightDM)