[Pkg-shadow-devel] Bug#385035: Login should not allow text to be entered between user and password

Matthew Flaschen matthew.flaschen at gatech.edu
Mon Aug 28 16:43:09 UTC 2006


Package: login
Version: 4.0.3-31sarge8

The problem is that after you type the username, but before the program 
begins taking password input, it is possible to type directly into the 
shell.  This means that if someone begins typing their password 
prematurely will have it displayed on screen, and logged.

Kernel: 2.4.27-2-386
libc: 2.3.6

Matthew Flaschen




More information about the Pkg-shadow-devel mailing list