lightdm.log should not be user readable

Bug #835996 reported by Dave Gilbert
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Light Display Manager
Fix Released
Medium
Unassigned
lightdm (Ubuntu)
Fix Released
Medium
Robert Ancell
Oneiric
Fix Released
Medium
Robert Ancell

Bug Description

lightdm seems to have created /var/log/lightdm/lightdm.log as :

-rw-r--r-- 1 root root 5166 2011-08-28 12:26 lightdm.log

I believe that should not be user readable, among other things in there we have
debug including data lengths from the greeter, login users, then details about the users sesssion
including the session cookie.

Dave

ProblemType: Bug
DistroRelease: Ubuntu 11.10
Package: lightdm 0.9.3-0ubuntu8
ProcVersionSignature: Ubuntu 3.0.0-9.14-generic 3.0.3
Uname: Linux 3.0.0-9-generic x86_64
Architecture: amd64
CheckboxSubmission: f2d10bd9f943a85b486a282e7840a570
CheckboxSystem: 0531969bcfd4f03af7405c98dc94a948
Date: Sun Aug 28 12:50:20 2011
InstallationMedia: Ubuntu 9.10 "Karmic Koala" - Release amd64 (20091027)
ProcEnviron:
 LANGUAGE=
 PATH=(custom, user)
 LANG=en_GB.UTF-8
 SHELL=/bin/bash
SourcePackage: lightdm
UpgradeStatus: Upgraded to oneiric on 2011-07-31 (28 days ago)

Related branches

CVE References

Revision history for this message
Dave Gilbert (ubuntu-treblig) wrote :
visibility: private → public
Changed in lightdm (Ubuntu):
importance: Undecided → Medium
milestone: none → ubuntu-11.10-beta-2
status: New → Triaged
Martin Pitt (pitti)
Changed in lightdm (Ubuntu Oneiric):
assignee: nobody → Robert Ancell (robert-ancell)
Changed in lightdm:
status: New → Triaged
importance: Undecided → Medium
Revision history for this message
Robert Ancell (robert-ancell) wrote :

Fixed in lightdm 0.9.6

Changed in lightdm (Ubuntu Oneiric):
status: Triaged → Fix Released
status: Fix Released → Fix Committed
Changed in lightdm:
status: Triaged → Fix Committed
Revision history for this message
Martin Pitt (pitti) wrote :

lightdm (0.9.6-0ubuntu1) oneiric; urgency=low

  * New upstream release:
    - Only unlock displays if switched to from greeter
    - Make log file not system readable
    - Write ~/.Xauthority inside the session process so it cannot be hijacked
    - Set PAM_TTY and PAM_XDISPLAY when opening PAM session
    - Add VNC server support
    - Do not write ~/.dmrc and ~/.Xauthority as root. [CVE-2011-3349]
  * debian/patches/00upstream_unlock_fix.patch:
  * debian/patches/04_dont_write_files_as_root.patch:
    - Applied upstream

Changed in lightdm (Ubuntu Oneiric):
status: Fix Committed → Fix Released
Changed in lightdm:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.