Debian Security Advisory
DSA-4783-1 sddm -- security update
- Date Reported:
- 05 Nov 2020
- Affected Packages:
- sddm
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 973748.
In Mitre's CVE dictionary: CVE-2020-28049. - More information:
-
Fabian Vogt discovered a flaw in sddm, a modern display manager for X11. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges.
For the stable distribution (buster), this problem has been fixed in version 0.18.0-1+deb10u1.
We recommend that you upgrade your sddm packages.
For the detailed security status of sddm please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sddm