First published: Thu May 22 2014(Updated: )
debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gdm-guest-session issue.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
LightDM | =1.0.0 | |
LightDM | =1.0.1 | |
LightDM | =1.0.2 | |
LightDM | =1.0.3 | |
LightDM | =1.0.4 | |
LightDM | =1.0.5 | |
LightDM | =1.1.0 | |
LightDM | =1.1.1 | |
LightDM | =1.1.2 | |
LightDM | =1.1.3 | |
LightDM | =1.1.4 | |
LightDM | =1.1.5 | |
LightDM | =1.1.6 | |
Ubuntu | =11.10 | |
=1.0.0 | ||
=1.0.1 | ||
=1.0.2 | ||
=1.0.3 | ||
=1.0.4 | ||
=1.0.5 | ||
=1.1.0 | ||
=1.1.1 | ||
=1.1.2 | ||
=1.1.3 | ||
=1.1.4 | ||
=1.1.5 | ||
=1.1.6 | ||
=11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0943 has a medium severity rating due to its local file deletion capabilities.
To fix CVE-2012-0943, upgrade Light Display Manager to version 1.0.6 or later or to 1.1.7 or later.
CVE-2012-0943 affects LightDM versions 1.0.0 through 1.0.5, and 1.1.0 through 1.1.6.
CVE-2012-0943 allows local users on Ubuntu 11.10 to delete arbitrary files, which can lead to data loss.
The LightDM vulnerability described in CVE-2012-0943 was attributed to Robert Ancell.