{"id":"USN-3255-1","summary":"lightdm vulnerability","details":"It was discovered that LightDM incorrectly handled home directory creation for\nguest users. A local attacker could use this issue to gain ownership of\narbitrary directory paths and possibly gain administrative privileges.\n","modified":"2026-04-22T09:35:08.710218Z","published":"2017-04-04T22:06:15Z","related":["UBUNTU-CVE-2017-7358"],"upstream":["CVE-2017-7358","UBUNTU-CVE-2017-7358"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-3255-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2017-7358"}],"affected":[{"package":{"name":"lightdm","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/lightdm@1.18.3-0ubuntu1.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.3-0ubuntu1.1"}]}],"versions":["1.16.4-0ubuntu1","1.17.0-0ubuntu1","1.17.1-0ubuntu1","1.17.1-0ubuntu2","1.17.2-0ubuntu1","1.17.3-0ubuntu1","1.17.4-0ubuntu1","1.17.5-0ubuntu2","1.17.6-0ubuntu1","1.18.0-0ubuntu1","1.18.0-0ubuntu2","1.18.1-0ubuntu1","1.18.2-0ubuntu1","1.18.2-0ubuntu2","1.18.3-0ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gir1.2-lightdm-1","binary_version":"1.18.3-0ubuntu1.1"},{"binary_name":"liblightdm-gobject-1-0","binary_version":"1.18.3-0ubuntu1.1"},{"binary_name":"liblightdm-qt-3-0","binary_version":"1.18.3-0ubuntu1.1"},{"binary_version":"1.18.3-0ubuntu1.1","binary_name":"liblightdm-qt5-3-0"},{"binary_name":"lightdm","binary_version":"1.18.3-0ubuntu1.1"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:16.04:LTS","cves":[{"id":"CVE-2017-7358","severity":[{"score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3255-1.json"}}],"schema_version":"1.7.5"}