Vulnerability CVE-2013-4331


Published: 2014-02-01   Modified: 2014-02-02

Description:
Light Display Manager (aka LightDM) 1.4.x before 1.4.3, 1.6.x before 1.6.2, and 1.7.x before 1.7.14 uses 0664 permissions for the temporary .Xauthority file, which allows local users to obtain sensitive information by reading the file.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
LightDM 1.7.13 local users obtain sensitive information
Yves-Alexis Pere...
02.02.2014

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Robert ancell -> Lightdm 

 References:
https://bugs.launchpad.net/lightdm/%2Bbug/685212

Copyright 2024, cxsecurity.com

 

Back to Top