Bug#395572: This one is security bug with high severity too

Anton Ivanov anton.ivanov at kot-begemot.co.uk
Wed Feb 1 08:05:04 UTC 2017


First of all - confirming the bug. The bug is still there in jessie.

Second, staying after the logout prevents the pam component of ecryptfs 
from unmounting the filesystem. It defeats the security of any ecryptfs 
system or other method.

Third, it breaks autofs/nfs deployments - mounts for $HOME remain mounted

Frankly, considering that there has been no intention to fix it since 
potato, I suggest we remove the package altogether as it defeats key 
security measures in other packages.
A.



More information about the pkg-gnome-maintainers mailing list