Security vulnerability in ldm >= 2.2, please upgrade to 2.2.7 or to a bugfix release

Stéphane Graber <stgraber-GeWIH/[email protected]> Mon, 12 Mar 2012 16:55:39 -0400
Newsgroups gmane.linux.terminal-server.devel,gmane.linux.terminal-server.general
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hello,

A few days ago Tenho Tuhkala reported in #ltsp that he managed to get
wwm to spawn a root xterm from ldm.

This was tracked down today to a rather big oversight in wwm where
although we removed some keybindings when we introduced it, we didn't
get rid of all of them.

One of these is "xterm" and is bound to KP_RETURN (enter key), anyone
doing that key sequence in ldm when something else isn't grabbing it
would get a root xterm. (For example doing alt+enter usually works)


This security issue would allow anyone who has physical access to a
thin client to get access to a root shell without easily being
detected (like one would by spoofing the tftp server for example).
Simply upgrading to 2.2.7 or another fixed version (see below) and
rebooting all your thin clients should be enough to fix the security
issue entirely.


Although someone couldn't use this security issue to access all your
thin clients at once, an attacker with physical access could have
installed key loggers or similar software on some specific thin clients.
We therefore recommend inspecting your logs and changing your
passwords if you are in an environment where this may be a problem.

This was fixed today in revision 1419 of ldm-trunk and released as ldm
2.2.7.

Affected versions are:
ldm-2.2              1360
ldm-2.2.1            1363
ldm-2.2.2            1386
ldm-2.2.3            1389
ldm-2.2.4            1399
ldm-2.2.5            1410
ldm-2.2.6            1418

The fix can be found at:
http://bazaar.launchpad.net/~ltsp-upstream/ltsp/ldm-trunk/revision/1419 so
distributions can easily cherry-pick it.
As you'll notice, it simply removes any remaining keybindings as they
weren't supposed to be there to start with.


The fix was coordinated between Ubuntu and Debian.
ldm 2.2.7 has just been uploaded to Debian unstable and will be synced
into Ubuntu Precise to ship in 12.04.

I'm also in the process of pushing security fixes to affected released
versions of Ubuntu:
 - Ubuntu 11.04, 2:2.2.1-0ubuntu1 => 2:2.2.1-0ubuntu1.1
 - Ubuntu 11.10, 2:2.2.4-0ubuntu1 => 2:2.2.4-0ubuntu1.1

Debian doesn't currently have any released version shipping ldm 2.2.x
so the bugfix will appear in testing as ldm 2.2.7 lands there.


In the near future, we plan on spawning the ldm greeter as nobody (or
similar non-privileged user) and only have the ldm backend run as root.
This should avoid any similar issue in our greeter code.

- -- 
Stéphane Graber
Ubuntu developer
http://www.ubuntu.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCgAGBQJPXmLLAAoJEMY4l01keS1nGLEP/2s1c5E5xe0WvxxLS/fvp+XW
8sWgu73aCZF8j7L7iJeCKJM1sJu1+61t2PFx+f+p8sls9UG7hzMU34Ukb9J76y8x
o8fziGaffvjZAvF/ljIXcrrA2d0SFbMH940djrfCWXsX70P6gI3yztAKmBQ2kbRJ
1eUYQABT/E/O+kgAAqVdqpjH2moKJuOt8sVflNJwKXc6xvMsfr2VnHjmk+nxU7p8
VViOBAEbmUXljjS8GhjySVx/CdimRNJnNozy1OxUbhoIJv7JsRQ7+uRhGOyUMahi
4gUkUqJzcDrjJ968+Tc9pRV1dnjpkFBXYRTYM6zsBf28AbF3YaQ1ysg3NT0+4Wbj
7DnMK6JlB+jNI57HZtI8kaCijNv6cvQK3Hi/P/XP5lpXN9TAs4wq20BsPUfH47HS
i4gq4rwZcXG3/QgGPk/oximHhB1HCBZvH6yBuNtxGo4zT9uZPQ96w1Ssd0l1/zvL
Rw5UxReYP1VXqR3U1FXub/tI/mRTZ7o3th4rtKv06r2rp/lDDcva0jwVN/0ULvBQ
uuJ/kkUS7rS3rUY2cGgobN27YwnfMVGNxHitFQooklWrZuQyxYjUeST7b+nQepsW
I42Ba0imn74TunZLygICbfPVY1rDe8vOcrB3ykrOlb9GTOQ6QA6wAq2+yEplKKqc
115VkrHoiBSFK6PGnM8G
=9MF6
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Try before you buy = See our experts in action!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-dev2
_____________________________________________________________________
Ltsp-developer mailing list.   To un-subscribe, or change prefs, goto:
      https://lists.sourceforge.net/lists/listinfo/ltsp-developer
For additional LTSP help,   try #ltsp channel on irc.freenode.net