daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm"
},
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm-dbg"
},
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm-dbgsym"
},
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm-theme-circles"
},
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm-theme-elarun"
},
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm-theme-maldives"
},
{
"binary_version": "0.13.0-1ubuntu5",
"binary_name": "sddm-theme-maui"
}
]
}