Root Access Vulnerability in LTSP LDM by LTSP
CVE-2019-20373
7.8HIGH
What is CVE-2019-20373?
The LTSP LDM, as of versions up to 2.18.06, has a vulnerability that permits root access for fat clients. This issue arises due to the LDM_USERNAME variable potentially being empty when the user's shell does not support Bourne shell syntax. This vulnerability is tied to the run-x-session script, which can lead to unauthorized access and potential system compromise.