The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201612-34 | third party advisory vendor advisory |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357 | third party advisory issue tracking |
https://bugzilla.redhat.com/show_bug.cgi?id=862324 | patch third party advisory issue tracking |
http://www.debian.org/security/2013/dsa-2777 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2013/10/01/9 | third party advisory mailing list |