** Description changed: Starting with ldm 2.2.x upstream switched to wwm as a minimal window manager for ldm, though it only recently was discovered that it ships with a keybinding allowing to spawn an xterm. As the ldm greeter runs as root, this essentially allows for a passwordless root shell to be spawned on any LTSP thin client since Ubuntu 11.04. - While definitely quite bad, it's not horribly bad as all thin clients are booted from the network with their filesystem downloaded cleartext from the network, we already consider them as non secure machines to start with. The fix upstream is to turn off all the keybindings in wwm as it was meant to be from the beginning. I commited the bugfix upstream and we'll release a new version today for upload to Debian and sync into Precise. + I'm going to provide two debdiffs in the next few minutes cherry-picking + the fix for Ubuntu 11.04 and 11.10. - I'm going to provide two debdiffs in the next few minutes cherry-picking the fix for Ubuntu 11.04 and 11.10. - - For the record, the keybinding is KP_RETURN. + For the record, the keybinding is KP_RETURN. Easiest way to trigger it + is by doing alt+enter or switching to the second workspace (alt+2) then + simply pressing enter. The original reporter for this security issue is "Tenho Tuhkala" with the bug tracked down and fixed by me.
-- You received this bug notification because you are a member of Edubuntu Bugsquad, which is subscribed to ldm in Ubuntu. https://bugs.launchpad.net/bugs/953340 Title: ldm 2.2.x (using wwm) contains a keybinding allowing the user to get a root shell To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ldm/+bug/953340/+subscriptions _______________________________________________ Mailing list: https://launchpad.net/~edubuntu-bugs Post to : edubuntu-bugs@lists.launchpad.net Unsubscribe : https://launchpad.net/~edubuntu-bugs More help : https://help.launchpad.net/ListHelp