Advisories ยป MGASA-2013-0286

Updated lightdm package fixes security vulnerability

Publication date: 19 Sep 2013
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-4331

Description

lightdm before 1.4.3, 1.6.2 and 1.7.14 created .Xauthority files with
world-readable permissions (CVE-2013-4331).

Additionally, an issue where a user logged into a graphical desktop
environment through lightdm would lose privleges to local devices (such as
the sound card) when using the 'su' command has been fixed.
                

References

SRPMS

3/core