CVE-2014-7272
published 2018-03-08CVE-2014-7272: Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a…
PriorityP340high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
32.5th percentile
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sddm | < sddm 0.11.0-2 (bookworm) | sddm 0.11.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| sddm_project | sddm | < 0.10.0 | 0.10.0 |
| sddm_project | sddm | >= 0 < 0.11.0-2 | 0.11.0-2 |
| sddm_project | sddm | >= 0 < 0.11.0-2 | 0.11.0-2 |
| sddm_project | sddm | >= 0 < 0.11.0-2 | 0.11.0-2 |
| sddm_project | sddm | >= 0 < 0.11.0-2 | 0.11.0-2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qgx-m88q-gp35: Simple Desktop Display Manager (SDDM) before 0
ghsa_unreviewed·2022-05-14
CVE-2014-7272 [HIGH] GHSA-2qgx-m88q-gp35: Simple Desktop Display Manager (SDDM) before 0
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
OSV
CVE-2014-7272: Simple Desktop Display Manager (SDDM) before 0
osv·2018-03-08·CVSS 7.8
CVE-2014-7272 [HIGH] CVE-2014-7272: Simple Desktop Display Manager (SDDM) before 0
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
Debian
CVE-2014-7272: sddm - Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain r...
vendor_debian·2014·CVSS 7.8
CVE-2014-7272 [HIGH] CVE-2014-7272: sddm - Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain r...
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race condition in the ~/.Xauthority chown case, but not other cases).
Scope: local
bookworm: resolved (fixed in 0.11.0-2)
bullseye: resolved (fixed in 0.11.0-2)
forky: resolved (fixed in 0.11.0-2)
sid: resolved (fixed in 0.11.0-2)
trixie: resolved (fixed in 0.11.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7272 sddm: several local privileges escalation issues [fedora-all]
bugzilla·2014-10-06·CVSS 7.8
CVE-2014-7272 [HIGH] CVE-2014-7272 sddm: several local privileges escalation issues [fedora-all]
CVE-2014-7272 sddm: several local privileges escalation issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2014-7272 sddm: several local privileges escalation issues
bugzilla·2014-10-06·CVSS 7.8
CVE-2014-7272 [HIGH] CVE-2014-7272 sddm: several local privileges escalation issues
CVE-2014-7272 sddm: several local privileges escalation issues
It was reported that sddm has several issues leading to local privilege escalation:
[1]
The xauth cookie handling code calls xauth binary via
popen() as root, which in turn dumps and creates files as root
in users ~.
[2]
After xauth has done its job, sddm chowns() the ~/.Xauthority
file to user. This is a race and a local root exploit.
[3]
The .xsession-errors file is created in ~ but as root.
This allows to destroy arbitrary system files.
Upstream patch is at [4].
[1] https://bugzilla.suse.com/show_bug.cgi?id=897788#c7
[2] https://bugzilla.suse.com/show_bug.cgi?id=897788#c8
[3] https://bugzilla.suse.com/show_bug.cgi?id=897788#c9
[4] https://github.com/sddm/sddm/pull/280
Discussion:
Created sddm tracking bugs for thi
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141494.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141550.htmlhttp://www.openwall.com/lists/oss-security/2014/10/06/4https://bugzilla.redhat.com/show_bug.cgi?id=1149610https://github.com/sddm/sddm/pull/280http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141494.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141550.htmlhttp://www.openwall.com/lists/oss-security/2014/10/06/4https://bugzilla.redhat.com/show_bug.cgi?id=1149610https://github.com/sddm/sddm/pull/280
2018-03-08
Published