LightDM 'xauthority.c' File Insecure File Permissions Vulnerability
BID:62329
Info
LightDM 'xauthority.c' File Insecure File Permissions Vulnerability
| Bugtraq ID: | 62329 |
| Class: | Design Error |
| CVE: |
CVE-2013-4331 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 03 2013 12:00AM |
| Updated: | Apr 13 2015 10:12PM |
| Credit: | Yves-Alexis Perez |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.04 freedesktop.org LightDM 1.7.13 freedesktop.org LightDM 1.6.1 freedesktop.org LightDM 1.4.2 |
| Not Vulnerable: |
freedesktop.org LightDM 1.7.14 freedesktop.org LightDM 1.6.2 freedesktop.org LightDM 1.4.3 |
Discussion
LightDM 'xauthority.c' File Insecure File Permissions Vulnerability
LightDM is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue by gaining access to a world-readable file and extracting sensitive information from it. Such information could aid in other attacks.
LightDM is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue by gaining access to a world-readable file and extracting sensitive information from it. Such information could aid in other attacks.
Exploit / POC
LightDM 'xauthority.c' File Insecure File Permissions Vulnerability
Attackers require local interactive access to an affected computer to exploit this issue.
Attackers require local interactive access to an affected computer to exploit this issue.
Solution / Fix
LightDM 'xauthority.c' File Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
LightDM 'xauthority.c' File Insecure File Permissions Vulnerability
References:
References:
- Light Display Manager (LightDM) Homepage (Freedesktop.org)