641
VMScore

CVE-2011-3349

Published: 19/11/2019 Updated: 03/12/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

lightdm prior to 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lightdm project lightdm

Vendor Advisories

Debian Bug report logs - #639151 Local privilege escalation Package: lightdm; Maintainer for lightdm is Debian Xfce Maintainers <debian-xfce@listsdebianorg>; Source for lightdm is src:lightdm (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 24 Aug 2011 16:36:04 UTC Severity: grave ...