Bug 1451243 (CVE-2017-8900) - CVE-2017-8900 lightdm: LightDM does not confine the user session for guest users
Summary: CVE-2017-8900 lightdm: LightDM does not confine the user session for guest u...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2017-8900
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-05-16 08:20 UTC by Adam Mariš
Modified: 2019-09-29 14:12 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2017-05-16 08:21:18 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2017-05-16 08:20:28 UTC
LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.


Note You need to log in before you can comment on or make changes to this bug.