Impact
Pardus LightDM Greeter before version 0.4.15 has an incorrect permission assignment that allows an attacker to view display contents that should be hidden, exposing sensitive information displayed during the login process or while the user is logged in. The flaw is catalogued as a CWE‑732 weakness, which means that system resources are granted broader access than intended, leading to a confidentiality breach.
Affected Systems
The vulnerability affects TÜBİTAK BİLGEM Software Technologies Research Institute’s Pardus LightDM Greeter. All installations of Pardus using this greeter with a version earlier than 0.4.15 are impacted. The remediation version is 0.4.15 or later; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.1 highlights a high severity resulting primarily from the potential loss of confidential data. The EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is inferred to be on systems where the greeter is running, requiring local or privileged access to read the screen, so the risk is primarily limited to local attackers or those who can interact with the user session. The absence of publicly documented exploits suggests that the threat is low to moderate until a potential zero‑day application emerges.
OpenCVE Enrichment