Comment 2 for bug 1668321

Revision history for this message
BIGUENET Quentin (qbiguenet) wrote : Re: Vulnerability in lightdm allow read/write/exec access on Ubuntu 16.04 Screenlock as lightdm user

Hi,

$ apt-cache policy unity-greeter
unity-greeter:
  Installé : 16.04.2-0ubuntu1
  Candidat : 16.04.2-0ubuntu1
 Table de version :
 *** 16.04.2-0ubuntu1 500
        500 http://fr.archive.ubuntu.com/ubuntu xenial/main amd64 Packages
        100 /var/lib/dpkg/status

'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
Content of /var/lib/polkit-1/localauthority/10-vendor.d/unity-greeter.pkla :

# DO NOT EDIT THIS FILE, it will be overwritten on update
# Place your local configurations under /etc/polkit-1/localauthority/

[Disable Controlling of Network Devices]
Identity=unix-user:lightdm
Action=org.freedesktop.NetworkManager.enable-disable-network;org.freedesktop.NetworkManager.enable-disable-wifi;org.freedesktop.NetworkManager.enable-disable-wwan;org.freedesktop.NetworkManager.enable-disable-wimax;
ResultActive=no
ResultInactive=no
ResultsAny=no

[Disable Sleep and Wake]
Identity=unix-user:lightdm
Action=org.freedesktop.NetworkManager.sleep-wake
ResultActive=no
ResultInactive=no
ResultsAny=no

[Disable WiFi Sharing]
Identity=unix-user:lightdm
Action=org.freedesktop.NetworkManager.wifi.share.protected;org.freedesktop.NetworkManager.wifi.share.open
ResultActive=no
ResultInactive=no
ResultsAny=no

[Disable Settings Modifications]
Identity=unix-user:lightdm
Action=org.freedesktop.NetworkManager.settings.modify.own;org.freedesktop.NetworkManager.settings.modify.system;org.freedesktop.NetworkManager.settings.modify.hostname
ResultActive=no
ResultInactive=no
ResultsAny=no

[Disable User Connections]
Identity=unix-user:lightdm
Action=org.freedesktop.NetworkManager.use-user-connections
ResultActive=no
ResultInactive=no
ResultsAny=no

[Enable Controlling of Network Connections]
Identity=unix-user:lightdm
Action=org.freedesktop.NetworkManager.network-control
ResultActive=yes
ResultInactive=no
ResultsAny=no