|
|
Subscribe / Log in / New account

Ubuntu alert USN-4533-1 (ldm)

From:  Avital Ostromich <avital.ostromich@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-4533-1] LTSP Display Manager vulnerabilities
Date:  Tue, 22 Sep 2020 17:04:20 -0400
Message-ID:  <cfae7936-257f-ed2b-5183-f0a8ae6f7863@canonical.com>

========================================================================== Ubuntu Security Notice USN-4533-1 September 22, 2020 ldm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: LTSP Display Manager could be made to escalate user privileges. Software Description: - ldm: LTSP display manager Details: Veeti Veteläinen discovered that the LTSP Display Manager (ldm) incorrectly handled user logins from unsupported shells. A local attacker could possibly use this issue to gain root privileges. (CVE-2019-20373) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: ldm 2:2.18.06-1+deb10u1build0.20.04.1 ldm-server 2:2.18.06-1+deb10u1build0.20.04.1 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4533-1 https://launchpad.net/bugs/1839431 Package Information: https://launchpad.net/ubuntu/+source/ldm/2:2.18.06-1+deb1... -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds