-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.3898
                           sddm security update
                              6 November 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           sddm
Publisher:         Debian
Operating System:  Debian GNU/Linux
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Increased Privileges -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-28049  

Original Bulletin: 
   http://www.debian.org/security/2020/dsa-4783

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running sddm check for an updated version of the software for their
         operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-4783-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
November 05, 2020                     https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : sddm
CVE ID         : CVE-2020-28049
Debian Bug     : 973748

Fabian Vogt discovered a flaw in sddm, a modern display manager for X11.
A local attacker can take advantage of a race condition when creating
the Xauthority file to escalate privileges.

For the stable distribution (buster), this problem has been fixed in
version 0.18.0-1+deb10u1.

We recommend that you upgrade your sddm packages.

For the detailed security status of sddm please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/sddm

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl+kDfFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0ThRA//X26U34fkNfzjBj0hOIGkS+G4qvWo+q0INoGR/D/aNWlUhPwMiOCnYl/r
YeyD0o2TRWBvuDL/Fx+TIAWETZK1NEwXhFtjgW5C2fv2QDhUI+8qG2Ge3ImxBxRZ
sC7JilbLihKU18NkIk8cmc6vRHZwwVXx1F3z2g1fFHs3gmdXM1yt4wESz7RHywms
0zo49pp7grp82EQlUgMYJjkIctHGbYGxc3dKWPXy1CaRtJO4NwYf4xnLJJRda4ft
uxbmgggbnc/ZHMsWZoWxVNhBcNPVBhcViwYPNFNxCvwXZVS/Cr9T+flLuaJfLr5O
NSBkO075XQf3gWbwrFBwS8RzDdj3LY+9wGCjwK2x8cueZWjRngyEpq9aZeEKkx9A
AnCQD5DoWk92/IIq122eyW+pgtApyDMbgBRMtMQc7E3HSlRdG9T1r8LhHSH58Tlv
zSv2vCCycPhJ7mIwZKkso6Bv+j6Ok/XIl3UFLZQsn8PIiYPVYR0QePB2YM55scfj
rOpKEE0Ru25a7I0ZC3hcK/KnVspCvg52JECvoO1UgoY7Hph2m98T+sNh4GS2lj04
FAy/sM+uxsnQqJo4iwtS8Ck+NC1kJkELXF5OPjMRdFxHTvBjNR+cnZ5vtbZmG9Av
OqKY2YKiYYVxfvGMg36XVvJoMfaL2Q/WuQ1S9U8CNqdFRZwIDr4=
=cUNM
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBX6TFXuNLKJtyKPYoAQgXkg//T0RpZ7l25ID25vNvareLheHefrlhv47h
hp8pWax3EnmjBMZkLLYKAw+BmwUUQkKu3019Ehiqu9vqgNN0S42nSZNP4P9C/qjp
UZ7CYqyNGuofWRo5kO1Qww5Se39rd387UksQOXjKZSvVX6Z3xPZAxdi3ttAkbizY
RJ3lqO06RNmgkYVrKV6EyKZWxs5xd9GJ6hfVI9wrjL1eQS7snmzo34ULeqz3aqG2
9yeIvj+2ItU18l0OxXpjqNmk+bxWyxxab+DRGy8Md8CVY5YLjgZ1YzJCm0FoBzcK
FR+UtPGgwlGwTx34IYi9puMyR1CUjRsPXlZ+pUBqnei/jTUHaSQ0RoWNi0sREF9F
aOTtcuzlv92G7wxfINi9cGlLE7CN+VKof8qcuXdiBi8vfTKHpbMe1eIN08f1lIQP
nfrFxpJnugaNYkgyNk5KR7hHIzHVf2tJOCfHjjGKuqMpWnagbKGxky6oOj0uuENp
vm5OpF8b8sNwpOQ568VL3uZO96IGSL1Ifm6kO1ArSorFGudrIZiPKBh1sPzOwa9z
in+6dSEd9PeUli6ggbmBs7H2Qz/BFnzNOcsrSZbjV/D2CWiA6ICW4/O358aUEH2p
1/FH44Hgc5JRTP2qYBkbXnguD8WkK9EuGOXHH2LZXhuoaJD6gfQNk0wcKYY1OM7/
mpWKyTBUwXQ=
=2Skx
-----END PGP SIGNATURE-----