Gnoppix Security Announcement - 2026-08-12T15:51:17.017-04:00

Gnoppix Security Advisory: LemonLDAP::NG Update Fixes Authentication Bypass

GSA-6434-1 addresses critical vulnerabilities in LemonLDAP::NG, a Web-SSO system. Attackers can bypass authentication or trigger denial of service. Upgrade immediately.

Impact

Affected versions: Gnoppix 24/25 (oldstable) and Gnoppix 26 (stable). The flaw allows remote attackers to manipulate security headers, leading to unauthorized access.

Critical warning: Exploitation requires no authentication. Users must patch instantly.

What to Do

  • Upgrade packages to the fixed versions listed in the advisory.
  • Restart services after installation to apply changes.
  • Monitor logs for suspicious authentication attempts.

Technical Details

The vulnerability stems from improper input validation in the session handling. This permits an attacker to inject malicious parameters. As a result, existing sessions can be hijacked.

Affected Distributions

  • Gnoppix 24/25 (oldstable): fixed in version 2.16.1-1+deb12u1.
  • Gnoppix 26 (stable): fixed in version 2.16.1-1+deb13u1.

The testing distribution (Gnoppix 27) receives updates via its regular cycle.

Recommendation

Apply the security update immediately. Review the original advisory for detailed CVE references. - Please update your systems.