Record summary

CVE-2017-7358 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBLightDM (Ubuntu 16.04/16.10) - 'Guest Account' Local Privilege EscalationExploitDB exploitby G. GeshevNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubJonPichel/CVE-2017-7358Repository PoCby JonPichelStars: 0Not analyzed10 files

23.3 KiB

GitHub

PoC details

References

7