Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 563108 (CVE-2015-0856) - <x11-misc/sddm-0.11.0-r4: does not prevent access to the KDE crash handler (CVE-2015-0856)
Summary: <x11-misc/sddm-0.11.0-r4: does not prevent access to the KDE crash handler (C...
Status: RESOLVED FIXED
Alias: CVE-2015-0856
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-15 08:24 UTC by Michael Palimaka (kensington)
Modified: 2016-11-25 06:17 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Palimaka (kensington) gentoo-dev 2015-10-15 08:24:45 UTC
From $URL:

Pavel Avgustinov discovered that sddm does not disable the KDE crash
handler, and certain themes would allow shell access to the sddm user
as a result in case of a crash.

Upstream fix:

https://github.com/sddm/sddm/commit/4cfed6b0a625593fb43876f04badc4dd99799d86
Comment 1 Jauhien Piatlicki (RETIRED) gentoo-dev 2015-10-16 20:10:15 UTC
Fixed with https://github.com/gentoo/gentoo/commit/b10b19ab1f8fb85673011d7f37f6cf1a6ab4bb2e
Comment 2 Jauhien Piatlicki (RETIRED) gentoo-dev 2015-10-17 08:09:50 UTC
Sorry, I forgot to do a revision bump, will do it in a moment.
Comment 3 Jauhien Piatlicki (RETIRED) gentoo-dev 2015-10-17 08:26:28 UTC
Revision bumped.
Comment 4 Jauhien Piatlicki (RETIRED) gentoo-dev 2015-10-17 09:27:20 UTC
I did a mistake again. sddm-0.11.0-r3 was stable, returning it back. Also patch apply fails, I'll fix it in a moment.
Comment 5 Jauhien Piatlicki (RETIRED) gentoo-dev 2015-10-17 09:36:11 UTC
No, ok, it is unstable (something bad with my eix may be), anyway I'm going to fix patch.
Comment 6 Jauhien Piatlicki (RETIRED) gentoo-dev 2015-10-17 10:08:25 UTC
Patch fixed. This bug can be processed further by security team.
Comment 7 Aaron Bauman (RETIRED) gentoo-dev 2016-02-15 12:26:52 UTC
CVE-2015-0856:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0856

daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.

Propose cleanup of previous ebuilds which are still vulnerable.
Comment 8 Manuel Rüger (RETIRED) gentoo-dev 2016-02-15 23:01:06 UTC
commit 995cfe07a14973a5e9207995fdb60c18e4442615
Author: Manuel Rüger <mrueg@gentoo.org>
Date:   Mon Feb 15 23:59:16 2016 +0100

    x11-misc/sddm: Remove vulnerable
    
    Package-Manager: portage-2.2.27
Comment 9 Aaron Bauman (RETIRED) gentoo-dev 2016-11-25 06:17:50 UTC
During the initial assesment it was unsure if root privileges could be gained through this crash.  After further review, privileges can only be escalated to that of the sddm user.  Redesignated as a B4.

GLSA Vote: No