[Bug 1064584] [NEW] Locked gnome session unlocks without password authentication

Launchpad Bug Tracker 1064584 at bugs.launchpad.net
Sun May 26 23:18:44 UTC 2013


*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Tim (darkxst):

When switching between users in ubuntu 12.10 using gdm a rather
unpleasant behaviour can occur when a locked session unlocks without
password authentication.

Steps to reproduce:
1. Login as user1 (password required)
2. Lock screen
3. Select login as other user
4. Login in user2 which does not require any password, e.g. guest
5. Logout user2
6. Screen returns to unlocked session for user1

It doesn't happen every time but rather frequently so I suspect some
sort of race involved.

ProblemType: Bug
DistroRelease: Ubuntu 12.10
Package: gdm 3.6.0-0ubuntu4
ProcVersionSignature: Ubuntu 3.5.0-17.27-generic 3.5.5
Uname: Linux 3.5.0-17-generic x86_64
ApportVersion: 2.6.1-0ubuntu1
Architecture: amd64
Date: Tue Oct  9 20:08:07 2012
InstallationMedia: Ubuntu 11.10 "Oneiric Ocelot" - Release amd64 (20111012)
SourcePackage: gdm
UpgradeStatus: Upgraded to quantal on 2012-09-07 (32 days ago)

** Affects: gnome-shell
     Importance: Medium
         Status: Fix Released

** Affects: gnome-shell (Ubuntu)
     Importance: Medium
         Status: Confirmed


** Tags: amd64 apport-bug quantal
-- 
Locked gnome session unlocks without password authentication
https://bugs.launchpad.net/bugs/1064584
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is subscribed to the bug report.



More information about the Ubuntu-sponsors mailing list