[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#253007: kdm: AutoLogin bypasses some necessary authorisation and stuff!



tag 253007 + unreproducible moreinfo
thanks

On Sun, Jun 06, 2004 at 02:06:30PM +0000, Luke Kenneth Casson Leighton wrote:
> Package: kdm
> Severity: normal
> 
> 
> i just ran fireflier-client-kde and rather than having the
> username of the AutoLogin user, it has root instead (because
> ff-c uses unistd.h's getlogin() function which returns the
> name of the logged in user)
> 
> also, i am running SE/Linux and i have had to use a patched
> version which doesn't rely on pam_selinux being in /etc/pam.d/kde.
> 
> AutoLogin is basically quite broken.
> 
> it would appear that the logged in user is still effectively root.
> 
> if i wasn't running SE/Linux this would be incredibly bad.

  pam file for that is kdm-np IIRC.

  moreover, I cannot reproduce that bug at all. do you still can ?

-- 
·O·  Pierre Habouzit
··O                                                madcoder@debian.org
OOO                                                http://www.madism.org

Attachment: signature.asc
Description: Digital signature


Reply to: