lightdm before 1.4.3, 1.6.2 and 1.7.14 created .Xauthority files with world-readable permissions (CVE-2013-4331).
Additionally, an issue where a user logged into a graphical desktop environment through lightdm would lose privleges to local devices (such as the sound card) when using the 'su' command has been fixed.