naming an new user 'admin' in gnome user managment compromises user groups/rights

Bug #327180 reported by Björn Rabethge
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-system-tools (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

Ubuntu 8.10 / gnome

When you add a new user using the gnome built in user managment and name the user 'admin' it will overwrite the privileged user group admin with a new group id (>1000) and delete all other users from this group.

As a result all other users (also the one performing the action) will loose admin privileges and sudo rights.

This step is also very hard to take back, a simple 'sudo adduser otherusers admin' wont help since the groupid is changed and even changing the gid back to the original value is not enough.

kde overcomes this problem by adding '_#' to the usergroup in case it allready exists. (ie 'admin_1').

I think this is a quite dangerous bug, since it affects especially inexperienced users which rely on the gui. Destroying the user groups managment with a username should not be possible.

I am at work right now and can specify the package. Will add later.

description: updated
Revision history for this message
Andy Loughran (andylockran) wrote :

Can confirm on jaunty. Using gnome inbuilt user administration tool.

Revision history for this message
Martin Meredith (mez) wrote :

Confirmed... OUCH!

Revision history for this message
Chris Coulson (chrisccoulson) wrote :

Thank you for your bug report. This bug has already been reported, but please feel free to report any other bugs you find.

Changed in gnome-system-tools:
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.