It was reported [1],[2] that when the fallback greeter is used in GDM3.x, if the disable-user-list setting is "true" (so a user list is not displayed, but entry fields for username and password), if a user enters their username and are then presented with a password prompt, if they were to click the "cancel" button then all of the user-interactive fields disappear. The user is then unable to login in or otherwise interact with the display manager, and must either kill X or reboot. There is no upstream fix as of yet. CVE-2013-7273 was assigned [3] to this issue. [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683338 [2] https://bugzilla.gnome.org/show_bug.cgi?id=704284 [3] http://seclists.org/oss-sec/2014/q1/40
Created gdm tracking bugs for this issue: Affects: fedora-all [bug 1050746]
This does not affect gdm 2.x.