Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 11.10 & 11.04 USN-1398-1 Critical LTSP Access Risk

ubuntu
Calendar Grey March 12, 2012
Scroller Ubuntu
LTSP Display Manager on Ubuntu identified with vulnerabilities that could permit unauthorized administrative access. Immediate updates suggested.
LTSP Display Manager could be made to run programs as an administrator.

Summary

LTSP Display Manager could be made to run programs as an administrator.

Software Description:

- ldm: LTSP display manager

Details:

Tenho Tuhkala discovered that the LTSP Display Manager (ldm) incorrectly

filtered keybindings. An attacker could use the default keybindings to

execute arbitrary commands as root at the login screen.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  ldm                             2:2.2.4-0ubuntu1.1

Ubuntu 11.04:
  ldm                             2:2.2.1-0ubuntu1.1

After a standard system update you need to restart the LTSP Display Manager
to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1398-1

CVE-2012-1166

Severity
critical
Lowest
Low
Medium
High
Critical

March 12, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.