CVE-2017-7358

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/04/2017
Last modified:
20/04/2025

Description

In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lightdm_project:lightdm:*:*:*:*:*:*:*:* 1.22.0 (including)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.10:*:*:*:*:*:*:*