CVE-2012-0943

Publication date 13 March 2012

Last updated 24 July 2024


Ubuntu priority

debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-6648 has been assigned for the gdm-guest-session issue.

Status

Package Ubuntu Release Status
gdm-guest-session 13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Ignored end of life
11.04 natty
Fixed 0.24ubuntu0.1
10.10 maverick
Fixed 0.17ubuntu0.1
10.04 LTS lucid
Fixed 0.15ubuntu0.1
8.04 LTS hardy Not in release
lightdm 13.04 raring
Fixed 1.1.7-0ubuntu2
12.10 quantal
Fixed 1.1.7-0ubuntu2
12.04 LTS precise
Fixed 1.1.7-0ubuntu2
11.10 oneiric
Fixed 1.0.6-0ubuntu1.6
11.04 natty
Not affected
10.10 maverick Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-1399-1
    • gdm-guest-session vulnerability
    • 13 March 2012
    • USN-1399-2
    • Light Display Manager vulnerability
    • 13 March 2012

Other references