Canonical · Lightdm · CVE-2017-7358
**Name of the Vulnerable Software and Affected Versions**
LightDM versions prior to 1.23.0, specifically versions through 1.22.0
**Description**
A directory traversal issue exists in the debian/guest-account.sh script of LightDM, allowing local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.
**Recommendations**
For versions through 1.22.0, update to version 1.23.0 or later to resolve the issue.