CVE-2012-1166: Canonical Ltsp Display Manager
High severity, CVSS 10.0. EPSS: 4.8% chance of exploitation in the next 30 days.
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
Affected products
- Canonical Ltsp Display Manager: version 2.2.4 only; version 2.2.5 only; version 2.2.6 only
- Canonical Ubuntu Linux: version 11.04 only; version 11.10 only
Published 2014-05-21. Last modified 2026-06-16.