PublicDate: 2008-04-29 13:09:00 UTC Candidate: CVE-2008-1293 References: https://ubuntu.com/security/notices/USN-610-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1293 Description: ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6). Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: ogra CVSS: Patches_ltsp: upstream_ltsp: not-affected dapper_ltsp: released (0.87.1) feisty_ltsp: released (5.0.7.1) gutsy_ltsp: released (5.0.39.1) hardy_ltsp: not-affected devel_ltsp: not-affected