MGASA-2014-0504
Dashboard / Vulnerabilities / MGASA-2014-0504
Summary: Updated sddm packages fix security vulnerabilities
Details: Sddm may in some cases allow unauthenticated logins as the sddm user (CVE-2014-7271). Sddm is vulnerable to a race condition in XAUTHORITY file generation (CVE-2014-7272). Sddm has been updated to version 0.10.0, fixing these issues and several other bugs, and adding new functionality. libxcb packages have been updated to work with sddm.
References: https://advisories.mageia.org/MGASA-2014-0504.html, https://bugs.mageia.org/show_bug.cgi?id=14238, https://github.com/sddm/sddm/releases/tag/v0.10.0, https://lists.fedoraproject.org/pipermail/package-announce/2014-October/141494.html
Affected packages
Package
Name: sddm
Purl: pkg:rpm/mageia/sddm?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
