CVE-2012-6648

Publication date 22 May 2014

Last updated 24 July 2024


Ubuntu priority

gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-2012-0943 per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-0943 is used for the guest-account issue.

Status

Package Ubuntu Release Status
gdm-guest-session 13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Ignored end of life
11.04 natty
Fixed 0.24ubuntu0.1
10.10 maverick
Fixed 0.17ubuntu0.1
10.04 LTS lucid
Fixed 0.15ubuntu0.1
8.04 LTS hardy Not in release
lightdm 13.04 raring
Fixed 1.1.7-0ubuntu2
12.10 quantal
Fixed 1.1.7-0ubuntu2
12.04 LTS precise
Fixed 1.1.7-0ubuntu2
11.10 oneiric
Fixed 1.0.6-0ubuntu1.6
11.04 natty
Not affected
10.10 maverick Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release