CVE-2012-6648
gdm-guest-session <= 0.24 - Arbitrary File Deletion via Space in /tmp Filename
Title source: llmDescription
gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-2012-0943 per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-0943 is used for the guest-account issue.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
https://launchpadlibrarian.net/96474113/gdm-guest-session.secure-cleanup.debdiff
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/953044
Patch, Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://ubuntu.com/usn/usn-1399-1
Scores
EPSS
0.0038
EPSS Percentile
30.0%
Details
CWE
CWE-264
Status
published
Products (8)
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
10.10
canonical/ubuntu_linux
11.04
gdm-guest-session_project/gdm-guest-session
0.20
gdm-guest-session_project/gdm-guest-session
0.21
gdm-guest-session_project/gdm-guest-session
0.22
gdm-guest-session_project/gdm-guest-session
0.23
gdm-guest-session_project/gdm-guest-session
< 0.24
Published
May 22, 2014
Tracked Since
Feb 18, 2026