lightdm vulnerability

Related Vulnerabilities: CVE-2013-4459  

Light Display Manager could be made to expose sensitive information locally.

Christian Prim discovered that Light Display Manager incorrectly applied the AppArmor security profile when the Guest account is used. A local attacker could use this issue to possibly gain access to sensitive information.

6 November 2013

lightdm vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 13.10

Summary

Light Display Manager could be made to expose sensitive information locally.

Software Description

  • lightdm - Display Manager

Details

Christian Prim discovered that Light Display Manager incorrectly applied the AppArmor security profile when the Guest account is used. A local attacker could use this issue to possibly gain access to sensitive information.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 13.10
lightdm - 1.8.4-0ubuntu1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to reboot your computer to make all the necessary changes.

References