CVE-2020-28049
published 2020-11-04CVE-2020-28049: An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to…
PriorityP432medium6.3CVSS 3.1
AVLACHPRLUINSUCHIHAN
EPSS
0.41%
34.1th percentile
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | sddm | < sddm 0.19.0-1 (bookworm) | sddm 0.19.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| sddm_project | sddm | < 0.19.0 | 0.19.0 |
| sddm_project | sddm | >= 0 < 0.19.0-1 | 0.19.0-1 |
| sddm_project | sddm | >= 0 < 0.19.0-1 | 0.19.0-1 |
| sddm_project | sddm | >= 0 < 0.19.0-1 | 0.19.0-1 |
| sddm_project | sddm | >= 0 < 0.19.0-1 | 0.19.0-1 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv6.3MEDIUM
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q868-g69p-72cw: An issue was discovered in SDDM before 0
ghsa_unreviewed·2022-05-24
CVE-2020-28049 [MEDIUM] CWE-362 GHSA-q868-g69p-72cw: An issue was discovered in SDDM before 0
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
OSV
CVE-2020-28049: An issue was discovered in SDDM before 0
osv·2020-11-04·CVSS 6.3
CVE-2020-28049 [MEDIUM] CVE-2020-28049: An issue was discovered in SDDM before 0
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Debian
CVE-2020-28049: sddm - An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X serve...
vendor_debian·2020·CVSS 6.3
CVE-2020-28049 [MEDIUM] CVE-2020-28049: sddm - An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X serve...
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Scope: local
bookworm: resolved (fixed in 0.19.0-1)
bullseye: resolved (fixed in 0.19.0-1)
forky: resolved (fixed in 0.19.0-1)
sid: resolved (fixed in 0.19.0-1)
trixie: resolved (fixed in 0.19.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file [epel-all]
bugzilla·2020-11-04·CVSS 6.3
CVE-2020-28049 [MEDIUM] CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file [epel-all]
CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file [fedora-all]
bugzilla·2020-11-04·CVSS 6.3
CVE-2020-28049 [MEDIUM] CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file [fedora-all]
CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file
bugzilla·2020-11-04·CVSS 6.3
CVE-2020-28049 [MEDIUM] CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file
CVE-2020-28049 sddm: local privilege escalation due to race condition in creation of the Xauthority file
sddm passes the -auth and -displayfd command line arguments when
starting the Xserver. It then waits for the display number to be
received from the Xserver via the `displayfd`, before the Xauthority
file specified via the `-auth` parameter is actually written. This
results in a race condition, creating a time window in which no valid
Xauthority file is existing while the Xserver is already running.
The X.Org server, when encountering a non-existing, empty or
corrupt/incomplete Xauthority file, will grant any connecting client
access to the Xorg display [2]. A local unprivileged attacker can thus
create an unauthorized connection to the Xserver and grab e.g. keyboard
input events from
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00031.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-28049https://github.com/sddm/sddm/blob/v0.19.0/ChangeLoghttps://github.com/sddm/sddm/releaseshttps://lists.debian.org/debian-lts-announce/2020/11/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GT3EX5NSQJJAKY63ENSMEDX6NYZLYY3S/https://security.gentoo.org/glsa/202402-02https://www.debian.org/security/2020/dsa-4783http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00031.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-28049https://github.com/sddm/sddm/blob/v0.19.0/ChangeLoghttps://github.com/sddm/sddm/releaseshttps://lists.debian.org/debian-lts-announce/2020/11/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GT3EX5NSQJJAKY63ENSMEDX6NYZLYY3S/https://security.gentoo.org/glsa/202402-02https://www.debian.org/security/2020/dsa-4783
2020-11-04
Published