bazaar.launchpad.netConfirmation
http://bazaar.launchpad.net/~lightdm-team/lightdm/trunk/revision/2478 CVE-2017-7358
HIGH
LightDM (Ubuntu 16.04/16.10) - 'Guest Account' Local Privilege Escalation
Record summary
CVE-2017-7358 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBLightDM (Ubuntu 16.04/16.10) - 'Guest Account' Local Privilege EscalationExploitDB exploitby G. GeshevNot analyzed1 file
Repository PoCs
GitHubJonPichel/CVE-2017-7358Repository PoCby JonPichelStars: 0Not analyzed10 files
References
797486vdb entry
http://www.securityfocus.com/bid/97486 launchpad.netConfirmation
https://launchpad.net/bugs/1677924 lists.freedesktop.orgConfirmation
https://lists.freedesktop.org/archives/lightdm/2017-April/001059.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-7358 41923exploit
https://www.exploit-db.com/exploits/41923 ubuntu.comConfirmation
https://www.ubuntu.com/usn/usn-3255-1