CVE-2012-0943: Low severity Robert Ancell Lightdm vulnerability
debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gdm-guest-session issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0943?
CVE-2012-0943 has a medium severity rating due to its local file deletion capabilities.
How do I fix CVE-2012-0943?
To fix CVE-2012-0943, upgrade Light Display Manager to version 1.0.6 or later or to 1.1.7 or later.
What versions of LightDM are affected by CVE-2012-0943?
CVE-2012-0943 affects LightDM versions 1.0.0 through 1.0.5, and 1.1.0 through 1.1.6.
What impact does CVE-2012-0943 have on Ubuntu 11.10?
CVE-2012-0943 allows local users on Ubuntu 11.10 to delete arbitrary files, which can lead to data loss.
Who is responsible for the LightDM issue described in CVE-2012-0943?
The LightDM vulnerability described in CVE-2012-0943 was attributed to Robert Ancell.