CVE-2015-0856

Fedora < 0.12.0 - Access Control

Title source: rule
STIX 2.1

Description

daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77099
Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171443.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/10/14/2

Scores

EPSS 0.0041
EPSS Percentile 33.9%

Details

CWE
CWE-264
Status published
Products (2)
fedoraproject/fedora 22
sddm_project/sddm < 0.12.0
Published Nov 24, 2015
Tracked Since Feb 18, 2026