USN-1382-1: Light Display Manager vulnerability
Ubuntu Security Notice USN-1382-1
5th March, 2012
lightdm vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 11.10
Summary
Light Display Manager would allow unintended access to file descriptors.
Software description
- lightdm - Display Manager
Details
Austin Clements discovered that Light Display Manager incorrectly leaked
file descriptors to child processes. A local attacker can use this to
bypass intended permissions and write to the log file, cause a denial of
service, or possibly have another unknown impact.
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 11.10:
- liblightdm-gobject-1-0 1.0.6-0ubuntu1.4
- liblightdm-qt-1-0 1.0.6-0ubuntu1.4
- lightdm 1.0.6-0ubuntu1.4
- lightdm-gtk-greeter 1.0.6-0ubuntu1.4
- lightdm-qt-greeter 1.0.6-0ubuntu1.4
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system update you need to reboot your computer to make
all the necessary changes.