First published: Sat Nov 23 2013(Updated: )
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
LightDM | =1.7.5 | |
LightDM | =1.7.6 | |
LightDM | =1.7.7 | |
LightDM | =1.7.8 | |
LightDM | =1.7.9 | |
LightDM | =1.7.10 | |
LightDM | =1.7.11 | |
LightDM | =1.7.12 | |
LightDM | =1.7.13 | |
LightDM | =1.7.14 | |
LightDM | =1.7.15 | |
LightDM | =1.7.16 | |
LightDM | =1.7.17 | |
LightDM | =1.7.18 | |
LightDM | =1.8.0 | |
LightDM | =1.8.1 | |
LightDM | =1.8.2 | |
LightDM | =1.8.3 | |
LightDM | =1.9.0 | |
LightDM | =1.9.1 | |
Ubuntu | =13.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4459 is considered a medium severity vulnerability due to its potential to bypass AppArmor restrictions.
To fix CVE-2013-4459, upgrade LightDM to version 1.9.2 or later.
CVE-2013-4459 affects users of LightDM versions 1.7.5 through 1.9.1.
CVE-2013-4459 allows local users to bypass intended restrictions by leveraging the Guest account.
A workaround for CVE-2013-4459 involves disabling the Guest account if immediate upgrading is not feasible.