CVE-2020-28049 - CVE House
Back to Database
Status published Unknown CVE-2020-28049

An issue was discovered in SDDM before 0.19.0. It incorrectly...

Vulnerability Description

An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28049

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

sddm project

View all reports →

Affected Software

sddm, leap, debian linux, fedora
Vulnerable Versions:
0, 15.1, 15.2, 9.0, 10.0, 33

Timeline

Official Publish: November 4th, 2020
Last Modified: October 15th, 2024
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.