On server login user can hack

Bug #124269 reported by filippo333
258
Affects Status Importance Assigned to Milestone
Ubuntu
Invalid
High
Brian Murray

Bug Description

I have a password protected account. When you switch users and go to: Options > Remote Login Via XDMCP... and then press cancel, the user can get into the currently logged in account without using a password.

ProblemType: Bug
Architecture: i386
Date: Thu Jul 5 19:58:54 2007
DistroRelease: Ubuntu 7.04
ExecutablePath: /usr/bin/gnome-panel
Package: gnome-panel 1:2.18.1-0ubuntu3
PackageArchitecture: i386
ProcCmdline: gnome-panel --sm-client-id default1
ProcCwd: /home/ubuntu
ProcEnviron:
 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: gnome-panel
Uname: Linux ubuntu 2.6.20-15-generic #2 SMP Sun Apr 15 07:36:31 UTC 2007 i686 GNU/Linux

Revision history for this message
filippo333 (filippo333) wrote :
Revision history for this message
Brian Murray (brian-murray) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Are you experiencing this with gdm or kdm? Which particular version of that package did you notice this with? You can check via 'dpkg -l gdm'. Thanks in advance.

Revision history for this message
Stéphane Graber (stgraber) wrote :

From what I've understood you've done the following :
You are logged in as xy, then choose the "Switch user" option of the session logout box which point you to a new gdm greeter.
At this point you entered a login, pressed enter and choose the "Remote login Via XDMCP" option.
The X server reloaded and you saw the XDMCP box with a Cancel button, clicking on it closed the XDMCP box and instead of reloading gdm and have a clean greeter you were redirected back to tty7 which was the xy's session from where you started.

So if the above is correct, it's not a real security issue as it'd have been if you had been able to login into someone else session which wasn't already opened, the problem is more on why didn't gnome-screesaver started on that session and locked the screen as it should (I wasn't able to reproduce this bug as after clicking on Cancel I was brought back on my Gnome-Screensaver asking for my password).

Is the above correct ?
If yes can you create a blank account and try again, to see if that's a gnome-screensaver configuration issue ?

Revision history for this message
filippo333 (filippo333) wrote :

This problem only occurs if you run Linux Ubuntu straight from the CD.

Revision history for this message
Brian Murray (brian-murray) wrote :

In your initial comment you mention that you have a password protected account but this is not the case, the user account on the Live CD does not have a password. So since there is no password this is not a bug.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.