LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.
References
Link | Resource |
---|---|
https://www.ubuntu.com/usn/usn-3285-1/ | Patch Vendor Advisory |
https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.html | Patch Vendor Advisory |
https://launchpad.net/bugs/1663157 | Issue Tracking Patch Vendor Advisory |
http://www.securityfocus.com/bid/98554 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-05-12 00:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-8900
Mitre link : CVE-2017-8900
JSON object : View
CWE
Products Affected
canonical
- ubuntu_linux
lightdm_project
- lightdm