{ "id": "CVE-2013-4459", "sourceIdentifier": "secalert@redhat.com", "published": "2013-11-23T18:55:04.673", "lastModified": "2024-11-21T01:55:36.593", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account." }, { "lang": "es", "value": "LightDM 1.7.5 hasta la 1.8.3 y 1.9.x anterior a 1.9.2, no aplica el perfil AppArmor a la cuenta de invitado, lo que permite a usuarios locales evitar las restricciones previstas por el aprovechamiento de la cuenta de invitado." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:N", "baseScore": 3.3, "accessVector": "LOCAL", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "LOW", "exploitabilityScore": 3.4, "impactScore": 4.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-264" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.5:*:*:*:*:*:*:*", "matchCriteriaId": "2F7FD9C8-C61D-4902-B592-938D1A17F04B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.6:*:*:*:*:*:*:*", "matchCriteriaId": "2A22930A-13A0-4722-8C3D-14CC53DCAF3B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.7:*:*:*:*:*:*:*", "matchCriteriaId": "969C4962-D760-482F-85E2-76DA424CFFB3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.8:*:*:*:*:*:*:*", "matchCriteriaId": "5F6416C0-33CA-4C4B-9BC7-0EF7A55DC465" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.9:*:*:*:*:*:*:*", "matchCriteriaId": "9618999D-5E24-45AA-9C3E-6B49F751263C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.10:*:*:*:*:*:*:*", "matchCriteriaId": "AEB6E3B7-1683-40F3-9F1E-04D16B8E836A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.11:*:*:*:*:*:*:*", "matchCriteriaId": "0A466891-DBC7-4EDD-B387-8D034C58DFAF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.12:*:*:*:*:*:*:*", "matchCriteriaId": "B9E83831-BEB3-4B4E-9CE3-AE06F1AB9633" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.13:*:*:*:*:*:*:*", "matchCriteriaId": "59E6D651-CBA2-4C07-9DA2-5E7B512AAF39" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.14:*:*:*:*:*:*:*", "matchCriteriaId": "27FEE5F4-8D39-4E9B-944B-AF730429CF3D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.15:*:*:*:*:*:*:*", "matchCriteriaId": "293066B8-5F58-41B4-94BF-173C2B9589C1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.16:*:*:*:*:*:*:*", "matchCriteriaId": "F3104527-B697-4CDC-8C00-BB8851C07623" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.17:*:*:*:*:*:*:*", "matchCriteriaId": "143E4B6C-FD88-4896-81FB-75F9842E058F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.7.18:*:*:*:*:*:*:*", "matchCriteriaId": "2381774C-B5F2-47C7-9B19-254832871BB7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.8.0:*:*:*:*:*:*:*", "matchCriteriaId": "7ABA8D67-4405-4E05-BB51-108A53557E28" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.8.1:*:*:*:*:*:*:*", "matchCriteriaId": "BA47DAC9-03D4-4A9A-9612-3A2599070598" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.8.2:*:*:*:*:*:*:*", "matchCriteriaId": "58E979D3-7083-4DC7-99DE-0445802E4441" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.8.3:*:*:*:*:*:*:*", "matchCriteriaId": "FA81568E-9894-4B49-B9E6-4FAE7ADE33DE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.9.0:*:*:*:*:*:*:*", "matchCriteriaId": "F4568827-76C7-4103-8457-78F2968E8967" }, { "vulnerable": true, "criteria": "cpe:2.3:a:robert_ancell:lightdm:1.9.1:*:*:*:*:*:*:*", "matchCriteriaId": "84A95133-1B2A-431B-A151-EECAD507BEE9" } ] } ] }, { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*", "matchCriteriaId": "7F61F047-129C-41A6-8A27-FFCBB8563E91" } ] } ] } ], "references": [ { "url": "http://lists.freedesktop.org/archives/lightdm/2013-October/000471.html", "source": "secalert@redhat.com" }, { "url": "http://lists.freedesktop.org/archives/lightdm/2013-October/000472.html", "source": "secalert@redhat.com" }, { "url": "http://www.ubuntu.com/usn/USN-2012-1", "source": "secalert@redhat.com" }, { "url": "https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/1243339", "source": "secalert@redhat.com", "tags": [ "Exploit" ] }, { "url": "http://lists.freedesktop.org/archives/lightdm/2013-October/000471.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://lists.freedesktop.org/archives/lightdm/2013-October/000472.html", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://www.ubuntu.com/usn/USN-2012-1", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/1243339", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit" ] } ] }