CVE-2013-4459
published 2013-11-23CVE-2013-4459: LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended…
PriorityP48low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.44%
36.1th percentile
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
| robert_ancell | lightdm | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqp2-x23v-m2mf: LightDM 1
ghsa_unreviewed·2022-05-17
CVE-2013-4459 [LOW] GHSA-wqp2-x23v-m2mf: LightDM 1
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
Ubuntu
Light Display Manager vulnerability
vendor_ubuntu·2013-11-06
CVE-2013-4459 Light Display Manager vulnerability
Title: Light Display Manager vulnerability
Summary: Light Display Manager could be made to expose sensitive information
locally.
Christian Prim discovered that Light Display Manager incorrectly applied
the AppArmor security profile when the Guest account is used. A local
attacker could use this issue to possibly gain access to sensitive
information.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to reboot your computer to
make all the necessary changes.
Debian
CVE-2013-4459: lightdm - LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor p...
vendor_debian·2013·CVSS 3.3
CVE-2013-4459 [LOW] CVE-2013-4459: lightdm - LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor p...
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4459 lightdm: guest account restrictions bypass
bugzilla·2013-11-25·CVSS 3.3
CVE-2013-4459 [LOW] CVE-2013-4459 lightdm: guest account restrictions bypass
CVE-2013-4459 lightdm: guest account restrictions bypass
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-4459 to
the following vulnerability:
Name: CVE-2013-4459
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4459
Assigned: 20130612
Reference: http://lists.freedesktop.org/archives/lightdm/2013-October/000471.html
Reference: http://lists.freedesktop.org/archives/lightdm/2013-October/000472.html
Reference: https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/1243339
Reference: UBUNTU:USN-2012-1
Reference: http://www.ubuntu.com/usn/USN-2012-1
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
Discussion
Bugzilla
CVE-2013-4459 lightdm: guest account restrictions bypass [fedora-all]
bugzilla·2013-11-25·CVSS 3.3
CVE-2013-4459 [LOW] CVE-2013-4459 lightdm: guest account restrictions bypass [fedora-all]
CVE-2013-4459 lightdm: guest account restrictions bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mul
http://lists.freedesktop.org/archives/lightdm/2013-October/000471.htmlhttp://lists.freedesktop.org/archives/lightdm/2013-October/000472.htmlhttp://www.ubuntu.com/usn/USN-2012-1https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/1243339http://lists.freedesktop.org/archives/lightdm/2013-October/000471.htmlhttp://lists.freedesktop.org/archives/lightdm/2013-October/000472.htmlhttp://www.ubuntu.com/usn/USN-2012-1https://bugs.launchpad.net/ubuntu/%2Bsource/lightdm/%2Bbug/1243339
2013-11-23
Published