ISOMAN

CVE

CVE-2017-7358

In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.

Severity
HIGH
CVSS
7.3
Published
Modified

Linked Releases

References

  1. http://bazaar.launchpad.net/~lightdm-team/lightdm/trunk/revision/2478
  2. http://www.securityfocus.com/bid/97486
  3. https://launchpad.net/bugs/1677924
  4. https://lists.freedesktop.org/archives/lightdm/2017-April/001059.html
  5. https://www.exploit-db.com/exploits/41923/
  6. https://www.ubuntu.com/usn/usn-3255-1/
  7. http://bazaar.launchpad.net/~lightdm-team/lightdm/trunk/revision/2478
  8. http://www.securityfocus.com/bid/97486
  9. https://launchpad.net/bugs/1677924
  10. https://lists.freedesktop.org/archives/lightdm/2017-April/001059.html
  11. https://www.exploit-db.com/exploits/41923/
  12. https://www.ubuntu.com/usn/usn-3255-1/