In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
{ "versions": [ { "introduced": "0" }, { "last_affected": "1.22.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7358.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "16.04" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "16.10" } ] } ]