CVE-2013-4459
LightDM 1.7.5-1.8.3 and 1.9.x < 1.9.2 - AppArmor Profile Bypass via Guest Account
Title source: llmDescription
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2012-1
Exploit x_refsource_misc
https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/1243339
Various Sources mailing-list
x_refsource_mlist
http://lists.freedesktop.org/archives/lightdm/2013-October/000471.html
Various Sources mailing-list
x_refsource_mlist
http://lists.freedesktop.org/archives/lightdm/2013-October/000472.html
Scores
EPSS
0.0044
EPSS Percentile
35.6%
Details
CWE
CWE-264
Status
published
Products (21)
canonical/ubuntu_linux
13.10
robert_ancell/lightdm
1.7.5
robert_ancell/lightdm
1.7.6
robert_ancell/lightdm
1.7.7
robert_ancell/lightdm
1.7.8
robert_ancell/lightdm
1.7.9
robert_ancell/lightdm
1.7.10
robert_ancell/lightdm
1.7.11
robert_ancell/lightdm
1.7.12
robert_ancell/lightdm
1.7.13
... and 11 more
Published
Nov 23, 2013
Tracked Since
Feb 18, 2026