2.1
CVSSv2

CVE-2012-0943

Published: 22/05/2014 Updated: 30/05/2014
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

debian/guest-account in Light Display Manager (lightdm) 1.0.x prior to 1.0.6 and 1.1.x prior to 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gdm-guest-session issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

robert ancell lightdm 1.0.2

robert ancell lightdm 1.0.1

robert ancell lightdm 1.0.0

robert ancell lightdm 1.1.6

robert ancell lightdm 1.1.5

robert ancell lightdm 1.1.0

canonical ubuntu linux 11.10

robert ancell lightdm 1.0.5

robert ancell lightdm 1.0.3

robert ancell lightdm 1.1.3

robert ancell lightdm 1.1.1

robert ancell lightdm 1.0.4

robert ancell lightdm 1.1.4

robert ancell lightdm 1.1.2

Vendor Advisories

gdm-guest-session could be made to delete files as the administrator ...
Light Display Manager could be made to delete files as the administrator ...

Exploits

source: wwwsecurityfocuscom/bid/52452/info Light Display Manager (LightDM) is prone to a local arbitrary-file-deletion vulnerability A local attacker can exploit this issue to delete arbitrary files with administrator privileges Light Display Manager (LightDM) 106 is vulnerable Other versions may also be affected /usr/sbin/guest ...