USN-4533-1: LTSP Display Manager vulnerabilities
Publication date
22 September 2020
Overview
LTSP Display Manager could be made to escalate user privileges.
Releases
Packages
- ldm - LTSP display manager
Details
Veeti Veteläinen discovered that the LTSP Display Manager (ldm)
incorrectly handled user logins from unsupported shells. A local attacker
could possibly use this issue to gain root privileges. (CVE-2019-20373)
Veeti Veteläinen discovered that the LTSP Display Manager (ldm)
incorrectly handled user logins from unsupported shells. A local attacker
could possibly use this issue to gain root privileges. (CVE-2019-20373)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 20.04 LTS focal | ldm – 2:2.18.06-1+deb10u1build0.20.04.1 | ||
| ldm-server – 2:2.18.06-1+deb10u1build0.20.04.1 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.