Vulnerabilities > CVE-2017-8900 - Local Security Bypass vulnerability in LightDM

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
lightdm-project
canonical
nessus

Summary

LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.

Vulnerable Configurations

Part Description Count
Application
Lightdm_Project
195
OS
Canonical
2

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2017-159A1060F6.NASL
    description - lightdm-1.24.0 - Disable guest login as system default preset (CVE-2017-8900) - Modernize spec-file Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2018-01-15
    plugin id105821
    published2018-01-15
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/105821
    titleFedora 27 : lightdm (2017-159a1060f6)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2017-66ADAFEB3B.NASL
    description - Disable guest login as system default preset (CVE-2017-8900) Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2017-09-15
    plugin id103232
    published2017-09-15
    reporterThis script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/103232
    titleFedora 25 : lightdm (2017-66adafeb3b)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2017-D793FEF58F.NASL
    description - lightdm-1.24.0 - Disable guest login as system default preset (CVE-2017-8900) - Modernize spec-file Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2017-09-15
    plugin id103236
    published2017-09-15
    reporterThis script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/103236
    titleFedora 26 : lightdm (2017-d793fef58f)
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-3285-1.NASL
    descriptionTyler Hicks discovered that LightDM did not confine the user session for guest users. An attacker with physical access could use this issue to access files and other resources that they should not be able to access. In the default installation, this includes files in the home directories of other users on the system. This update fixes the issue by disabling the guest session. It may be re-enabled in a future update. Please see the bug referenced below for instructions on how to manually re-enable the guest session. Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id100156
    published2017-05-12
    reporterUbuntu Security Notice (C) 2017-2019 Canonical, Inc. / NASL script (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/100156
    titleUbuntu 16.10 / 17.04 : lightdm vulnerability (USN-3285-1)