Back to search
CVE-2011-3349
Published: Nov 19, 2019
Modified: Aug 6, 2024
PUBLISHED
Description
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
| Vendor | Product | Versions |
|---|---|---|
lightdm | lightdm | affected before 0.9.6 |
References
https://security-tracker.debian.org/tracker/CVE-2011-3349
x_refsource_MISC
https://access.redhat.com/security/cve/cve-2011-3349
x_refsource_MISC
https://www.securityfocus.com/bid/50506
x_refsource_MISC
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639151
x_refsource_MISC
https://bugs.launchpad.net/debian/+source/lightdm/+bug/834079
x_refsource_MISC
https://seclists.org/oss-sec/2011/q3/393
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now