CVE-2012-1166
published 2014-05-21CVE-2012-1166: The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN…
PriorityP359critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.84%
91.0th percentile
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ltsp_display_manager | — | — |
| canonical | ltsp_display_manager | — | — |
| canonical | ltsp_display_manager | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vx5j-qfg3-qhp3: The default keybindings for wwm in LTSP Display Manager (ldm) 2
ghsa_unreviewed·2022-05-17
CVE-2012-1166 [HIGH] CWE-78 GHSA-vx5j-qfg3-qhp3: The default keybindings for wwm in LTSP Display Manager (ldm) 2
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
Ubuntu
LTSP Display Manager vulnerability
vendor_ubuntu·2012-03-12
CVE-2012-1166 LTSP Display Manager vulnerability
Title: LTSP Display Manager vulnerability
Summary: LTSP Display Manager could be made to run programs as an administrator.
Tenho Tuhkala discovered that the LTSP Display Manager (ldm) incorrectly
filtered keybindings. An attacker could use the default keybindings to
execute arbitrary commands as root at the login screen.
Instructions: After a standard system update you need to restart the LTSP Display Manager
to make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-21
Published