PT-2008-6902 · Linux Terminal Server+1 · Ldm+4
Nico Golde
·
Publicado
1970-01-01
·
Atualizado
2018-10-03
·
CVE-2008-1293
CVSS v2.0
4.8
Média
| Vetor | AV:A/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ltsp-server-standalone versions (affected versions not specified)
ltsp-server versions (affected versions not specified)
ltsp-client-builder versions (affected versions not specified)
ltsp-client versions (affected versions not specified)
ldm versions 0.99 and 2
Description
The issue concerns multiple vulnerabilities in the ltsp-server-standalone, ltsp-server, ltsp-client-builder, ltsp-client, and ldm packages of the Debian GNU/Linux operating system. These vulnerabilities can be exploited by an attacker to compromise the confidentiality and integrity of protected information. In the case of ldm in Linux Terminal Server Project (LTSP), it passes the -ac option to the X server on each LTSP client, allowing remote attackers to connect to this server via TCP port 6006, also known as display :6.
Recommendations
For ltsp-server-standalone, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For ltsp-server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For ltsp-client-builder, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For ltsp-client, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For ldm versions 0.99 and 2, consider restricting access to the X server on each LTSP client to minimize the risk of exploitation.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ldm
Ltsp-Client
Ltsp-Client-Builder
Ltsp-Server
Ltsp-Server-Standalone