VulnerabilityModified
CVE-2017-8900
LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.
MEDIUM 4.6EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.
- CVSS 3.0
- 4.6 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- lightdm project/lightdm
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/98554Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1663157Issue Tracking, Patch, Vendor Advisory
- https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.htmlPatch, Vendor Advisory
- https://www.ubuntu.com/usn/usn-3285-1/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98554Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1663157Issue Tracking, Patch, Vendor Advisory
- https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-8900.htmlPatch, Vendor Advisory
- https://www.ubuntu.com/usn/usn-3285-1/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.