Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 493716 (CVE-2013-4459) - <x11-misc/lightdm-{1.8.4,1.9.2} : Access restriction bypass via Guest account (CVE-2013-4459)
Summary: <x11-misc/lightdm-{1.8.4,1.9.2} : Access restriction bypass via Guest account...
Status: RESOLVED FIXED
Alias: CVE-2013-4459
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-09 06:26 UTC by GLSAMaker/CVETool Bot
Modified: 2013-12-23 15:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-12-09 06:26:43 UTC
CVE-2013-4459 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4459):
  LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the
  AppArmor profile to the Guest account, which allows local users to bypass
  intended restrictions by leveraging the Guest account.
Comment 1 Agostino Sarubbo gentoo-dev 2013-12-09 09:08:49 UTC
Keywords for x11-misc/lightdm:
            |                           | u   |  
            | a a             p     s   | n   |  
            | l m   h i m m   p s   p   | u s | r
            | p d a p a 6 i p c 3   a x | s l | e
            | h 6 r p 6 8 p p 6 9 s r 8 | e o | p
            | a 4 m a 4 k s c 4 0 h c 6 | d t | o
------------+---------------------------+-----+-------
  1.0.11    | o + o o o o o o o o o o + | # 0 | gentoo
   1.2.2-r3 | o ~ ~ o o o o o o o o o ~ | #   | gentoo
   1.4.0    | o + + o o o o ~ o o o o + | o   | gentoo
   1.4.0-r2 | o + ~ o o o o ~ o o o o + | o   | gentoo
   1.4.3    | o ~ ~ o o o o ~ o o o o ~ | #   | gentoo
   1.6.2    | o ~ ~ o o o o ~ o o o o ~ | #   | gentoo
  1.7.16    | o ~ ~ o o o o ~ o o o o ~ | #   | gentoo
  1.7.18    | o ~ ~ o o o o ~ o o o o ~ | #   | gentoo
   1.8.5    | o ~ ~ o o o o ~ o o o o ~ | o   | gentoo
[M]1.9.5    | o ~ ~ o o o o ~ o o o o ~ | o   | gentoo
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2013-12-09 20:20:52 UTC
I am sorry but comment #1 makes no sense to me. The layout is very hard to read so it's not clear to me what you want me to do here.
Comment 3 Chris Reffett (RETIRED) gentoo-dev Security 2013-12-10 00:45:53 UTC
He's saying that the versions affected by this CVE are all ~, so no bumping needed. Please clean up versions that match " LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2," which would be 1.7.16 and 1.7.18.
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2013-12-22 13:37:29 UTC
(In reply to Chris Reffett from comment #3)
> He's saying that the versions affected by this CVE are all ~, so no bumping
> needed. Please clean up versions that match " LightDM 1.7.5 through 1.8.3
> and 1.9.x before 1.9.2," which would be 1.7.16 and 1.7.18.

Thanks. Done

+  22 Dec 2013; Markos Chandras <hwoarang@gentoo.org> -lightdm-1.7.16.ebuild,
+  -lightdm-1.7.18.ebuild:
+  Remove ebuilds affected by CVE-2013-4459. Bug #493716
+