Candidate: CVE-2015-8308 PublicDate: 2017-08-24 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8308 http://git.lxde.org/gitweb/?p=lxde/lxdm.git;a=commitdiff;h=e8f387089e241360bdc6955d3e479450722dcea3 https://bugzilla.redhat.com/show_bug.cgi?id=1268900 http://advisories.mageia.org/MGASA-2015-0411.html http://www.openwall.com/lists/oss-security/2015/11/20/2 Description: LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=805659 Priority: high Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_lxdm: upstream_lxdm: released (0.5.3-1) precise_lxdm: ignored (reached end-of-life) precise/esm_lxdm: DNE (precise was needs-triage) trusty_lxdm: ignored (reached end-of-life) trusty/esm_lxdm: DNE (trusty was needed) vivid_lxdm: ignored (reached end-of-life) vivid/stable-phone-overlay_lxdm: DNE vivid/ubuntu-core_lxdm: DNE wily_lxdm: ignored (reached end-of-life) xenial_lxdm: not-affected (0.5.3-1) yakkety_lxdm: ignored (reached end-of-life) zesty_lxdm: ignored (reached end-of-life) artful_lxdm: ignored (reached end-of-life) bionic_lxdm: not-affected (0.5.3-1) cosmic_lxdm: not-affected (0.5.3-1) disco_lxdm: not-affected (0.5.3-1) devel_lxdm: not-affected (0.5.3-1)