Hi,
* Piotr Engelking <[email protected]> [2009-07-11 14:35]:
> Package: slim
> Version: 1.3.0-2
> Severity: grave
> Tags: security
> Justification: user security hole
> X-Debbugs-Cc: [email protected]
> 
> Typing 'console' in the SLiM login prompt opens a gnome terminal running
> login(1). Opening a new terminal from the terminal menu (File -> Open
> Terminal) opens a gnome terminal running a root shell.

This is not really a bug but a feature, you can disable it 
editing /etc/slim.conf. However I agree this is not really a 
nice feature in a default configuration. I think a big fat 
note to README.Debian should be added to warn users of the 
possible implications.

Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - [email protected] - GPG: 0xA0A0AAAA
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpdAN6uezoLV.pgp
Description: PGP signature

Reply via email to