Bug#721388: gdm3: anyone can change the user's next session
Vincent Lefevre
vincent at vinc17.net
Tue Sep 10 13:19:47 UTC 2013
On 2013-09-10 11:23:37 +0200, Laurent Bigonville wrote:
> I tried to reproduce this on a machine running GDM 3.8 and I definitely
> cannot reproduce this. To save the default session of a user you really
> need to enter the password of this user, and as soon as you are hitting
> escape or enter with a wrong password, the session of the user is reset
> to the saved one.
With gdm 3.4, the session name is not reset. And this is reproducible
here. There might be a change in gdm 3.8.
> I guess that adding a timeout to un-select the user (return from the
> screen where you need to enter the password to the one (main) were you
> select the user) could mitigate this issue. I'll open an upstream bug
> for this.
Thanks. More comments there...
--
Vincent Lefèvre <vincent at vinc17.net> - Web: <http://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <http://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)
More information about the pkg-gnome-maintainers
mailing list