From 995bb111ca330cf1ff550973a4a35fb6e3e9c720 Mon Sep 17 00:00:00 2001 From: Robert Ancell Date: Wed, 5 Apr 2017 10:35:02 +1200 Subject: * SECURITY UPDATE: Directory traversal allowing arbitrary directory ownership and privilege escalation (LP: #1677924) - debian/guest-account.sh: Detect existing malicious guest user home dirs before proceeding with guest user creation - CVE-2017-7358 --- debian/changelog | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/debian/changelog b/debian/changelog index cb22c03e..9a32ee47 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,13 @@ +lightdm (1.22.0-0ubuntu2) zesty; urgency=medium + + * SECURITY UPDATE: Directory traversal allowing arbitrary directory + ownership and privilege escalation (LP: #1677924) + - debian/guest-account.sh: Detect existing malicious guest user home dirs + before proceeding with guest user creation + - CVE-2017-7358 + + -- Robert Ancell Wed, 05 Apr 2017 10:34:32 +1200 + lightdm (1.22.0-0ubuntu1) zesty; urgency=medium * Allow guest sessions to talk to Mir (allowing unity8) -- cgit v1.2.1