[5770] in bugtraq

home help back first fref pref prev next nref lref last post

visible passwd bug in kdm ?

daemon@ATHENA.MIT.EDU (Sascha Runschke)
Thu Dec 11 00:52:15 1997

Date: 	Wed, 10 Dec 1997 22:48:49 +0100
Reply-To: Sascha Runschke <decker@MATRIX.PING.DE>
From: Sascha Runschke <decker@MATRIX.PING.DE>
To: BUGTRAQ@NETSPACE.ORG

-----BEGIN PGP SIGNED MESSAGE-----


Hi,

it seems that there is a bug in the login procedure of the kdm environment.
If you type your passwd when prompted for it and afterwards try to mark the
invisible passwd with the mouse, it suddenly becomes visible.

I don't think it's that dangerous, but there might be a situation where you
cannot end your login-sequence and someone else is able to access your
station.

I did not check the code yet, because I do not use kdm. But maybe
I'll have a look later.

This bug was reported by as@ibm.net in de.comp.os.linux.x
Message-ID: <x47m9dwee7.fsf@lehre2000.iwi.uni-sb.de>

regards
        sascha

- --
Sascha Runschke                           eMail : decker@matrix.ping.de
Tel: +49-(0)177-2767693                           IRCNet,EFNet : Decker
        ## Linux 2.0 - The choice of the new generation ##
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3in
Charset: latin1

iQCVAwUBNI8OOw5fVlcX77C1AQFdGAQA1Jq1Cajigge0LxBHFq7tXrtuNWtcArT2
ZrEXCThi9hhHOvqnRMNoqpxdrEBoHUB7x79u3qjPVBfMqz/Lday5mrjppitxyb9B
tAdlyU7IKA4eFaUovAuD5IMOpGycDfmg8YUGa61TW2jcMKFshz7K5MAQCJpqASHM
1MIPfeeVnAM=
=Qr4x
-----END PGP SIGNATURE-----

home help back first fref pref prev next nref lref last post