Executive brief
Pardus LightDM Greeter is the login screen component used in the Pardus Linux distribution. An incorrect permission configuration in versions before 0.4.15 allows attackers to exploit access control mechanisms, potentially gaining unauthorized access to the system during or after the login process.
Technical details
This vulnerability is classified as an Incorrect Permission Assignment for Critical Resource (CWE-732). The LightDM Greeter component fails to properly enforce access controls on critical resources, allowing an attacker with local access to exploit misconfigured permissions. No network access is required; exploitation occurs on the local system where the vulnerable greeter is running. An attacker can leverage this to escalate privileges or bypass authentication controls. The issue is fixed in version 0.4.15 and later.
Affected products
- TÜBİTAK BİLGEM Pardus LightDM Greeter before 0.4.15
Timeline
- 2026-09-09: disclosed