daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "sddm",
"binary_version": "0.13.0-1ubuntu5"
},
{
"binary_name": "sddm-dbg",
"binary_version": "0.13.0-1ubuntu5"
},
{
"binary_name": "sddm-dbgsym",
"binary_version": "0.13.0-1ubuntu5"
},
{
"binary_name": "sddm-theme-circles",
"binary_version": "0.13.0-1ubuntu5"
},
{
"binary_name": "sddm-theme-elarun",
"binary_version": "0.13.0-1ubuntu5"
},
{
"binary_name": "sddm-theme-maldives",
"binary_version": "0.13.0-1ubuntu5"
},
{
"binary_name": "sddm-theme-maui",
"binary_version": "0.13.0-1ubuntu5"
}
]
}