Bug#721388: gdm3: anyone can change the user's next session

Vincent Lefevre vincent at vinc17.net
Tue Sep 10 13:19:47 UTC 2013


On 2013-09-10 11:23:37 +0200, Laurent Bigonville wrote:
> I tried to reproduce this on a machine running GDM 3.8 and I definitely
> cannot reproduce this. To save the default session of a user you really
> need to enter the password of this user, and as soon as you are hitting
> escape or enter with a wrong password, the session of the user is reset
> to the saved one.

With gdm 3.4, the session name is not reset. And this is reproducible
here. There might be a change in gdm 3.8.

> I guess that adding a timeout to un-select the user (return from the
> screen where you need to enter the password to the one (main) were you
> select the user) could mitigate this issue. I'll open an upstream bug
> for this.

Thanks. More comments there...

-- 
Vincent Lefèvre <vincent at vinc17.net> - Web: <http://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <http://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)



More information about the pkg-gnome-maintainers mailing list