PT-2017-17173 · Canonical+3 · Lightdm+4

Frederic Bardy

+1

·

Published

2017-03-09

·

Updated

2019-10-03

·

CVE-2017-6590

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions network-manager-applet versions 12.04 LTS through 16.10
Description A local attacker could exploit this issue at the default Ubuntu login screen to access local files and execute arbitrary commands as the lightdm user. The exploitation requires physical access to the locked computer, with Wi-Fi turned on, and an access point that allows certificate-based login. This could allow an attacker to open a nautilus window, browse directories, and open applications like Firefox, potentially for downloading malicious binaries.
Recommendations For versions 12.04 LTS through 16.10, consider restricting access to the network-manager-applet at the login screen until a patch is available. As a temporary workaround, disabling Wi-Fi at the login screen or requiring a password for Wi-Fi access could minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6590
OPENSUSE-SU-2024:10603-1

Affected Products

Debian
Firefox
Lightdm
Nautilus
Network-Manager-Applet