Bug#834178: gdm3: Password visible as plaintext during gdm3 login

Conrad J.C. Hughes (for Debian package stuff) debbugs at xrad.org
Mon Aug 29 15:16:14 UTC 2016


Package: gdm3
Version: 3.14.1-7
Followup-For: Bug #834178

Dear Maintainer,

I can confirm this bug, or something closely related: I'd booted my computer
but not logged in; after coming back to it the screen had blanked, but I typed
in my username and password anyway.  As the screen came back up I saw my
password visible in plaintext just before the successful login kicked in.
Couldn't trivially reproduce unfortunately.

Showing login password on-screen is a bit of a dangerous problem.  I'll
continue to try reproducing, but it's obviously a bit of a Heisenbug
unfortunately.

Conrad



-- System Information:
Debian Release: 8.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.16.0-4-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gdm3 depends on:
ii  accountsservice                       0.6.37-3+b1
ii  adduser                               3.113+nmu3
ii  dconf-cli                             0.22.0-1
ii  dconf-gsettings-backend               0.22.0-1
ii  debconf [debconf-2.0]                 1.5.56
ii  gir1.2-gdm3                           3.14.1-7
ii  gnome-session [x-session-manager]     3.14.0-2
ii  gnome-session-bin                     3.14.0-2
ii  gnome-settings-daemon                 3.14.2-3
ii  gnome-shell                           3.14.4-1~deb8u1
ii  gnome-terminal [x-terminal-emulator]  3.14.1-1+deb8u1
ii  gsettings-desktop-schemas             3.14.1-1
ii  libaccountsservice0                   0.6.37-3+b1
ii  libaudit1                             1:2.4-1+b1
ii  libc6                                 2.19-18+deb8u4
ii  libcanberra-gtk3-0                    0.30-2.1
ii  libcanberra0                          0.30-2.1
ii  libgdk-pixbuf2.0-0                    2.31.1-2+deb8u5
ii  libgdm1                               3.14.1-7
ii  libglib2.0-0                          2.42.1-1+b1
ii  libglib2.0-bin                        2.42.1-1+b1
ii  libgtk-3-0                            3.14.5-1+deb8u1
ii  libpam-modules                        1.1.8-3.1+deb8u1+b1
ii  libpam-runtime                        1.1.8-3.1+deb8u1
ii  libpam-systemd                        215-17+deb8u4
ii  libpam0g                              1.1.8-3.1+deb8u1+b1
ii  librsvg2-common                       2.40.5-1+deb8u2
ii  libselinux1                           2.3-2
ii  libsystemd0                           215-17+deb8u4
ii  libwrap0                              7.6.q-25
ii  libx11-6                              2:1.6.2-3
ii  libxau6                               1:1.0.8-1
ii  libxdmcp6                             1:1.1.1-1+b1
ii  libxrandr2                            2:1.4.2-1+b1
ii  lsb-base                              4.1+Debian13+nmu1
ii  metacity [x-window-manager]           1:3.14.3-1
ii  mutter [x-window-manager]             3.14.4-1~deb8u1
ii  policykit-1                           0.105-8
ii  ucf                                   3.0030
ii  x11-common                            1:7.7+7
ii  x11-xserver-utils                     7.7+3+b1
ii  xfce4-session [x-session-manager]     4.10.1-10
ii  xfce4-terminal [x-terminal-emulator]  0.6.3-1+b1
ii  xfwm4 [x-window-manager]              4.10.1-3
ii  xterm [x-terminal-emulator]           312-2

Versions of packages gdm3 recommends:
ii  at-spi2-core               2.14.0-1
ii  desktop-base               8.0.2
ii  gnome-icon-theme           3.12.0-1
ii  gnome-icon-theme-symbolic  3.12.0-1
ii  x11-xkb-utils              7.7+1
ii  xserver-xephyr             2:1.16.4-1
ii  xserver-xorg               1:7.7+7
ii  zenity                     3.14.0-1

Versions of packages gdm3 suggests:
ii  gnome-orca            3.14.0-4+deb8u1
ii  libpam-gnome-keyring  3.14.0-1+b1

-- debconf information:
  gdm3/daemon_name: /usr/sbin/gdm3
* shared/default-x-display-manager: lightdm



More information about the pkg-gnome-maintainers mailing list