Lucene search

K
cveRedhatCVE-2013-4331
HistoryFeb 02, 2014 - 12:55 a.m.

CVE-2013-4331

2014-02-0200:55:04
CWE-264
redhat
web.nvd.nist.gov
28
cve-2013-4331
light display manager
lightdm
permission vulnerability
sensitive information disclosure
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0

Percentile

5.1%

Light Display Manager (aka LightDM) 1.4.x before 1.4.3, 1.6.x before 1.6.2, and 1.7.x before 1.7.14 uses 0664 permissions for the temporary .Xauthority file, which allows local users to obtain sensitive information by reading the file.

Affected configurations

Nvd
Node
robert_ancelllightdmMatch1.4.0
OR
robert_ancelllightdmMatch1.4.1
OR
robert_ancelllightdmMatch1.4.2
OR
robert_ancelllightdmMatch1.6.0
OR
robert_ancelllightdmMatch1.6.1
OR
robert_ancelllightdmMatch1.7.0
OR
robert_ancelllightdmMatch1.7.1
OR
robert_ancelllightdmMatch1.7.2
OR
robert_ancelllightdmMatch1.7.3
OR
robert_ancelllightdmMatch1.7.4
OR
robert_ancelllightdmMatch1.7.5
OR
robert_ancelllightdmMatch1.7.6
OR
robert_ancelllightdmMatch1.7.7
OR
robert_ancelllightdmMatch1.7.8
OR
robert_ancelllightdmMatch1.7.9
OR
robert_ancelllightdmMatch1.7.10
OR
robert_ancelllightdmMatch1.7.11
OR
robert_ancelllightdmMatch1.7.12
OR
robert_ancelllightdmMatch1.7.13
VendorProductVersionCPE
robert_ancelllightdm1.4.0cpe:2.3:a:robert_ancell:lightdm:1.4.0:*:*:*:*:*:*:*
robert_ancelllightdm1.4.1cpe:2.3:a:robert_ancell:lightdm:1.4.1:*:*:*:*:*:*:*
robert_ancelllightdm1.4.2cpe:2.3:a:robert_ancell:lightdm:1.4.2:*:*:*:*:*:*:*
robert_ancelllightdm1.6.0cpe:2.3:a:robert_ancell:lightdm:1.6.0:*:*:*:*:*:*:*
robert_ancelllightdm1.6.1cpe:2.3:a:robert_ancell:lightdm:1.6.1:*:*:*:*:*:*:*
robert_ancelllightdm1.7.0cpe:2.3:a:robert_ancell:lightdm:1.7.0:*:*:*:*:*:*:*
robert_ancelllightdm1.7.1cpe:2.3:a:robert_ancell:lightdm:1.7.1:*:*:*:*:*:*:*
robert_ancelllightdm1.7.2cpe:2.3:a:robert_ancell:lightdm:1.7.2:*:*:*:*:*:*:*
robert_ancelllightdm1.7.3cpe:2.3:a:robert_ancell:lightdm:1.7.3:*:*:*:*:*:*:*
robert_ancelllightdm1.7.4cpe:2.3:a:robert_ancell:lightdm:1.7.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0

Percentile

5.1%