Bug 57136 - Bad: I can start xserver on ttyx from pts/0 when no user is logged in.
Summary: Bad: I can start xserver on ttyx from pts/0 when no user is logged in.
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: vnc   
(Show other bugs)
Version: 7.2
Hardware: All Linux
high
medium
Target Milestone: ---
Assignee: Tim Waugh
QA Contact: David Lawrence
URL:
Whiteboard:
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2001-12-05 17:37 UTC by Enrico Alan Romani
Modified: 2007-03-27 03:50 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2001-12-05 17:44:27 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Enrico Alan Romani 2001-12-05 17:37:52 UTC
From Bugzilla Helper:
User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; PCM_04d)

Description of problem:
If I log in on pts/0 with vnc and in the Xterm i give the command startx. 
The X Server start on ttyX and the user that is on the local terminal can 
use the system with no login. If I close the session of VNC the X Server 
on tty stand up. Otherwise if I close the X Session from pts/0 the X 
Server crash.

Version-Release number of selected component (if applicable):
3.3

How reproducible:
Always

Steps to Reproduce:
1.Log in as root
2.Type vncserver
3.type exit and logout
4.From remote PC login with VNC
5.In the Xterm type startx
6.Close the VNC window!
7.If you re-login from VNC and close or Ctr-c on Xterm the Gnome on tty1 
crash

	

Actual Results:  1.The Gnome go up on tty/1 with no user logged and stay 
alive

Additional info:

Comment 1 Tim Waugh 2001-12-05 17:44:21 UTC
I don't see the security problem.  How is this different from doing the same 
thing from within an ssh or telnet session?  Can you explain it in more detail 
please?

Thanks.


Comment 2 Tim Waugh 2001-12-19 13:17:52 UTC
Closing.  I think that what you are seeing is expected behaviour.



Note You need to log in before you can comment on or make changes to this bug.