{ "schema_version": "1.4.0", "id": "GHSA-7fp6-mjg4-r496", "modified": "2022-05-24T17:06:02Z", "published": "2022-05-24T17:06:02Z", "aliases": [ "CVE-2019-20373" ], "details": "LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support for Bourne shell syntax. This is related to a run-x-session script.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-20373" }, { "type": "WEB", "url": "https://git.launchpad.net/~ltsp-upstream/ltsp/+git/ldm/commit/?id=c351ac69ef63ed6c84221cef73e409059661b8ba" }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00007.html" }, { "type": "WEB", "url": "https://www.debian.org/security/2020/dsa-4601" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-01-09T23:15:00Z" } }