[Bug 48450] Security flaw that current session is NOT locked when switch user is invoked

Julian Yap julianokyap at gmail.com
Mon Jun 5 01:35:45 UTC 2006


Public bug reported:

This also relate to Launchpad bug 47005 where I have added additional
comments.

To reproduce bug:
1. Log in as user 'A'.  X session starts up on Virtual Console 7.
2. Invoke the 'Quit...' dialog.
3. Click on 'Switch User'.  Another GDM login screen is started up on Virtual Console 8.
4. Switch back to Virtual Console 7 using CTRL+ALT+7.  Session is NOT locked and you are free to do as you please as user 'A'.

This is a regression from Breezy which employed XScreensaver vs. Gnome
Screensaver and used gdmflexiserver as the Fast User switching
mechanism.

** Affects: gnome-session (Ubuntu)
       Severity: Normal
       Priority: (none set)
         Status: Unconfirmed

-- 
Security flaw that current session is NOT locked when switch user is invoked
https://launchpad.net/bugs/48450




More information about the desktop-bugs mailing list