CVE-2012-6648: Canonical Ubuntu Linux
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-2012-0943 per ADT1/ADT2 due to different codebases and affected versions. CVE-2012-0943 is used for the guest-account issue.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 10.10 only; version 11.04 only
- Gdm-Guest-Session Project Gdm-Guest-Session: up to and including 0.24; version 0.20 only; version 0.21 only; version 0.22 only; version 0.23 only
Published 2014-05-22. Last modified 2026-06-16.