[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2436-1] sddm security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2436-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
November 06, 2020                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : sddm
Version        : 0.14.0-4+deb9u2
CVE ID         : CVE-2020-28049
Debian Bug     : #973748

It was discovered that there was an issue in the sddm display manager
where local unprivileged users could create a connection to the X
server.

For Debian 9 "Stretch", this problem has been fixed in version
0.14.0-4+deb9u2.

We recommend that you upgrade your sddm packages.

For the detailed security status of sddm please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/sddm

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl+lJSUACgkQHpU+J9Qx
Hlg56Q//ctZuYZ9qCxddqqNN4hj5p/gQHfVFR4kyuXjId55Ag7+vVvL8j2Dyqh4+
cMllqRlLRMHfsmyGAaJ5YBeRv0+UJl4+ycj8SFWfRWY2mOYM0HT6dURBURy1m9XW
4G1l2szk8QqX3G6ovv4hS678VVdfbqDKjeEKAdGLDfFibMPTOEKSvlik5zQwvdaA
+uR3J2rM7yECNXCIal6kDLzdOQjps69/HOXfhBDeBnSdRstMxZkGbJSfRcBZP1fr
ObBNTgsfoE1GXeKaCYjb8oYbCGlmk/ReDoWNJ4cLTg0T98cGgFb4n0YLwU4u2213
G08BmKtjgashUl66ciwWiUc6zP7QSJOiozBx2d0du/a//k6x8tfFAqx/8PrQtEfA
AB/Ev5Vm4m9Ozqf/SMWNW7WccvnlwDe+skCXuyaEW/rsFXb7wcOe8Z8zdRcFIHhE
453nitjr50Cc5dKf9grtq4hpOYX2p/wfb37GLRHQkMGkFyEI5IIOTtbyMsijPk/P
RpVlQzvD19B91NydUpmydcob+ZmuPpUCOFP8txPfNxjmvTcPvYZvKNsujS/N63mg
dxfSFWNKksQElhCiWR8jrf/F9gpJVCgWLCYBsfX+Vz/5UmbTS19TZ7fDhu6Yh3jB
0wE9C2cI6wZXP/rG2QmeIVzGyCJ8QIZdCUXEFEL5tcU7urfhcqY=
=oLl+
-----END PGP SIGNATURE-----


Reply to: