LWN.net Logo

ldm: command execution as root

Package(s):ldm CVE #(s):CVE-2012-1166
Created:March 13, 2012 Updated:March 14, 2012
Description: From the Ubuntu advisory:

Tenho Tuhkala discovered that the LTSP Display Manager (ldm) incorrectly filtered keybindings. An attacker could use the default keybindings to execute arbitrary commands as root at the login screen.

Alerts:
Ubuntu USN-1398-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds