[Bug 296604] Re: Sugar-Emulator has no access control

David Farning dfarning at gmail.com
Mon Feb 1 18:32:52 GMT 2010

This has been fixed as of the most recent release of sugar .88 on 10.4

** Changed in: sugar
   Importance: Unknown => Critical

** Changed in: sugar
       Status: Confirmed => Fix Released

Sugar-Emulator has no access control
You received this bug notification because you are a member of Sugar
Team, which is subscribed to sugar in ubuntu.

Status in Sugar Learning Platform: Fix Released
Status in “sugar” package in Ubuntu: Triaged

Bug description:
Binary package hint: sugar

Sugar-Emulator uses the '-ac' flag in the Xephyr command line, with turns off access control. 

This means that anyone on the network can attach to the display/keyboard/mouse and interfer with the operation of Sugar (such as running xeyes, which goes full screen and can not be cancelled!).

With Xephyr on display :1
simon at destiny:~$ netstat -an
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State      
tcp        0      0  *               LISTEN         
tcp6       0      0 :::6001                 :::*                    LISTEN  


More information about the Ubuntu-sugarteam mailing list