Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 3271 - gdm-1.1.0-35 silently fails if home directory is 777
gdm-1.1.0-35 silently fails if home directory is 777
Product: Red Hat Linux
Classification: Retired
Component: gdm (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Elliot Lee
Depends On:
  Show dependency treegraph
Reported: 1999-06-04 12:59 EDT by nelson
Modified: 2008-05-01 11:37 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 1999-10-29 10:38:07 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description nelson 1999-06-04 12:59:41 EDT
If a user with a world-writeable directory tries to log in,
gdm will accept their password, clear the screen as if to
start the session, and then immediately kill the session and
return to the login box. No error messages are presented,
and we couldn't even find any explanation in a log file

I'm not sure if the bug is in gdm itself or the login
scripts that Redhat 6.0 uses. I have also submitted this as
a Gnome bug.
Comment 1 nelson 1999-06-04 13:00:59 EDT
This is listed as Gnome bug report #1393
Comment 2 David Lawrence 1999-06-04 17:39:59 EDT
I have verified this to be true on a test lab machine with a stock 6.0
intall. I created a sample user account. chmod 777 that users home
directory. Then using gdm attempted to login as the sample user with
out success. It would come back to the gdm login screen. I then chmod
755 the home directory and then was able to successfully login to the
gnome desktop.
Comment 3 nelson 1999-06-07 11:31:59 EDT
This might just be a good security measure - with xauth style
security, a world-writeable home directory is a really bad idea.
If this is correct behaviour, then the "fix" should be to make
sure the user understands why they weren't allowed to log in.
Some sort of visible error message...
Comment 4 Elliot Lee 1999-08-31 19:54:59 EDT
Assign to mkj for now.
Comment 5 Elliot Lee 1999-10-29 10:38:59 EDT
Try getting the gdm-2.0beta2-13 from RHL 6.1

Note You need to log in before you can comment on or make changes to this bug.