PT-2020-6147 · Ltsp+1 · Ltsp Ldm+1

Veeti Veteläinen

·

Published

2020-01-09

·

Updated

2020-09-22

·

CVE-2019-20373

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LTSP LDM versions prior to 2.18.07
Description The issue is related to the run-x-session script and allows for fat-client root access due to the potential empty value of the LDM USERNAME variable if the user's shell lacks support for Bourne shell syntax. This is a result of insecure privilege management, which can be exploited to elevate privileges to the level of a superuser.
Recommendations For LTSP LDM versions prior to 2.18.07, update to version 2.18.07 or later to resolve the issue. As a temporary workaround, consider restricting access to the run-x-session script until a patch is available.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03181
CVE-2019-20373
DLA-2064-1
DSA-4601-1
USN-4533-1

Affected Products

Ltsp Ldm
Ubuntu