10
CVSSv2

CVE-2012-1166

Published: 21/05/2014 Updated: 31/05/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x prior to 2.2.7 allow remote malicious users to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 11.10

canonical ltsp display manager 2.2.6

canonical ubuntu linux 11.04

canonical ltsp display manager 2.2.5

canonical ltsp display manager 2.2.4

Vendor Advisories

Debian Bug report logs - #663645 [CVE-2012-1166] ldm allows for a passwordless root shell Package: ldm; Maintainer for ldm is Debian LTSP Maintainers <team+ltsp@trackerdebianorg>; Source for ldm is src:ldm (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Mon, 12 Mar 2012 22:45:01 UTC Sev ...
LTSP Display Manager could be made to run programs as an administrator ...