CVE-2008-1293: Medium severity linux terminal server project vulnerability
Published Apr 29, 2008
·Updated
ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6).
Affected Software
2 affected components
LTSP Linux Terminal Server Project=0.99
LTSP Linux Terminal Server Project=2
Event History
Apr 29, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1293?
CVE-2008-1293 is considered to be of medium severity due to potential exposure of services to remote attackers.
2
How do I fix CVE-2008-1293?
To fix CVE-2008-1293, ensure that the -ac option is not passed to the X server on LTSP clients.
3
Which versions of the Linux Terminal Server Project are affected by CVE-2008-1293?
CVE-2008-1293 affects Linux Terminal Server Project versions 0.99 and 2.
4
What is the vulnerability in CVE-2008-1293 about?
CVE-2008-1293 allows remote attackers to connect via TCP port 6006 due to improper configuration of the X server.
5
What could happen if CVE-2008-1293 is exploited?
If exploited, CVE-2008-1293 could lead to unauthorized access to the X server, exposing sensitive information.