CVE-2019-20373
—CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
Description
LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support for Bourne shell syntax. This is related to a run-x-session script.
In the news0 stories
No ingested article mentions this CVE yet.