Bug 486120
Summary: | xorg-x11-server: Xorg server built without PAM support | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Tomas Hoger <thoger> | |
Component: | xorg-x11-server | Assignee: | Adam Jackson <ajax> | |
Status: | CLOSED ERRATA | QA Contact: | desktop-bugs <desktop-bugs> | |
Severity: | medium | Docs Contact: | ||
Priority: | medium | |||
Version: | 5.3 | CC: | cmeadors, jbardin, k.georgiou, mgordon, xgl-maint, zcerza | |
Target Milestone: | rc | |||
Target Release: | --- | |||
Hardware: | All | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | Doc Type: | Bug Fix | ||
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 582710 (view as bug list) | Environment: | ||
Last Closed: | 2010-03-30 08:34:06 UTC | Type: | --- | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 506535 | |||
Bug Blocks: |
Description
Tomas Hoger
2009-02-18 15:22:41 UTC
This request was evaluated by Red Hat Product Management for inclusion in a Red Hat Enterprise Linux maintenance release. Product Management has requested further review of this request by Red Hat Engineering, for potential inclusion in a Red Hat Enterprise Linux Update release for currently deployed products. This request is not yet committed for inclusion in an Update release. I will second this request. In the default config, it seems that a remote user could start up an xserver, and then bring up a fake terminal, or login screen to do with as they wish. Since the local terminal automatically jumps to the the new tty, a local user coming upon the system may not realize what's going on. Please correct me if this isn't as big a security concern as I imagine (I haven't done proof of concept), but any admin who switched from an initdefault if 5 to 3 has this configuration to worry about. I checked into debian, and they have their own wrapper for X (Xwrapper.config and xserver-xwrapper.c), that allows configuration for rootonly, console, or anybody. This request was evaluated by Red Hat Product Management for inclusion in a Red Hat Enterprise Linux maintenance release. Product Management has requested further review of this request by Red Hat Engineering, for potential inclusion in a Red Hat Enterprise Linux Update release for currently deployed products. This request is not yet committed for inclusion in an Update release. 2281401 build (dist-5E-qu-candidate, /cvs/dist:rpms/xorg-x11-server/RHEL-5:xorg-x11-server-1_1_1-48_74_el5) completed successfully MODIFIED An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2010-0259.html |