LWN.net Logo

ldm: authentication bypass/information disclosure

Package(s):ldm CVE #(s):CVE-2008-1293
Created:April 28, 2008 Updated:May 7, 2008
Description:

From the Debian advisory:

Christian Herzog discovered that within the Linux Terminal Server Project, it was possible to connect to X on any LTSP client from any host on the network, making client windows and keystrokes visible to that host.

Alerts:
Ubuntu USN-610-1 2008-05-06
Debian DSA-1561-1 2008-04-28

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds