Comment 0 for bug 834079

Revision history for this message
Yves-Alexis Perez (corsac) wrote :


as you were on CC: I guess you're already aware, but reporting so it can be tracked upstream.

Short version:

Long version: .dmrc and Xauthority files are written by lightdm running as root while they're in user controlled folders. An user can, via a symlink, overwrite root-owned files. It doesn't look like it can achieve easily privilege-escalation (since the content is quite fixed) but it's still bad.

Basically the correct fix seems to have workers process which would setuid() to the user before writing content to those files.

There's no CVE affected yet.