In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
{ "binaries": [ { "binary_name": "gir1.2-lightdm-1", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-gobject-1-0", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-gobject-1-0-dbgsym", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-gobject-1-dev", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-gobject-1-doc", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-qt-3-0", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-qt-3-0-dbgsym", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-qt-dev", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-qt5-3-0", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-qt5-3-0-dbgsym", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "liblightdm-qt5-3-dev", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "lightdm", "binary_version": "1.18.3-0ubuntu1.1" }, { "binary_name": "lightdm-dbgsym", "binary_version": "1.18.3-0ubuntu1.1" } ], "availability": "No subscription required" }