CVE-2013-4459

LightDM 1.7.5-1.8.3 and 1.9.x < 1.9.2 - AppArmor Profile Bypass via Guest Account

Title source: llm
STIX 2.1

Description

LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2012-1
Various Sources mailing-list x_refsource_mlist
http://lists.freedesktop.org/archives/lightdm/2013-October/000471.html
Various Sources mailing-list x_refsource_mlist
http://lists.freedesktop.org/archives/lightdm/2013-October/000472.html

Scores

EPSS 0.0044
EPSS Percentile 35.6%

Details

CWE
CWE-264
Status published
Products (21)
canonical/ubuntu_linux 13.10
robert_ancell/lightdm 1.7.5
robert_ancell/lightdm 1.7.6
robert_ancell/lightdm 1.7.7
robert_ancell/lightdm 1.7.8
robert_ancell/lightdm 1.7.9
robert_ancell/lightdm 1.7.10
robert_ancell/lightdm 1.7.11
robert_ancell/lightdm 1.7.12
robert_ancell/lightdm 1.7.13
... and 11 more
Published Nov 23, 2013
Tracked Since Feb 18, 2026