[ldm] [CVE-2008-1293] information disclosure

Bug #227295 reported by disabled.user
258
Affects Status Importance Assigned to Milestone
ldm (Debian)
Fix Released
Unknown
ldm (Ubuntu)
Fix Released
Medium
Oliver Grawert
Declined for Hardy by Oliver Grawert
Declined for Intrepid by Oliver Grawert
Dapper
Fix Released
Medium
Oliver Grawert
Feisty
Fix Released
Medium
Oliver Grawert
Gutsy
Fix Released
Medium
Oliver Grawert

Bug Description

Binary package hint: ldm

References:
DSA-1561-1 (http://www.debian.org/security/2008/dsa-1561)

Quoting:
"Christian Herzog discovered that within the Linux Terminal Server Project,
it was possible to connect to X on any LTSP client from any host on the
network, making client windows and keystrokes visible to that host."

Revision history for this message
Oliver Grawert (ogra) wrote :

this is fixed in hardy and intrepid

Revision history for this message
Oliver Grawert (ogra) wrote :

confirmed for dapper,feisty and gutsy

Changed in ldm:
status: New → Confirmed
Changed in ldm:
status: Unknown → Fix Released
Revision history for this message
Oliver Grawert (ogra) wrote :
Revision history for this message
Oliver Grawert (ogra) wrote :
Revision history for this message
Oliver Grawert (ogra) wrote :
Kees Cook (kees)
Changed in ldm:
assignee: nobody → keescook
status: Confirmed → In Progress
Revision history for this message
Kees Cook (kees) wrote :
Changed in ldm:
status: In Progress → Fix Released
assignee: nobody → ogra
importance: Undecided → Medium
status: New → Fix Released
assignee: nobody → ogra
importance: Undecided → Medium
status: New → Fix Released
assignee: nobody → ogra
importance: Undecided → Medium
status: New → Fix Released
assignee: keescook → ogra
importance: Undecided → Medium
Revision history for this message
emmanuel (emmanuel-inl) wrote :

I can't login anymore with this correction ...

Here is a better patch (I can add LM_DIRECTX to true and i can login with .Xauthority)

Changed in ldm:
status: Fix Released → Invalid
Revision history for this message
Kees Cook (kees) wrote :

Please open a new bug if you're experiencing regressions.

Changed in ldm:
status: Invalid → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.