found 633652 1.5.6-1
severity 633652 grave
thanks
I'm raising the severity of this bug. I feel it is inappropriate for any
more heel dragging to take place. It is embarrassment enough that root
is no longer to use X programs on Debian, including system management
tools specifically designed for root to use. If one does the following,
the whole X session becomes locked. The users half edited letters etc.
are taken for ransom.

# su - nobody
No directory, logging in with HOME=/
nobody@jidanni2:/$ env
SHELL=/bin/sh
TERM=xterm
USER=nobody
MAIL=/var/mail/nobody
PATH=/usr/local/bin:/usr/bin:/bin:/usr/bin/X11:/usr/games
PWD=/
SHLVL=1
HOME=/
LOGNAME=nobody
DISPLAY=:0
XAUTHORITY=/home/jidanni/.Xauthority
_=/usr/bin/env
nobody@jidanni2:/$ emacs /tmp/ee.txt

Only an expert user who knows CTRL ALT F1 and pstree etc. will
be able to kill the emacs and recover his X session. pstree -aAl shows
  |-bash /home/jidanni/.xsession
  |   `-xterm -class UXTerm -title uxterm -u8 -bg hotpink4 -title # -name # -e 
su
  |       `-su
  |           `-bash
  |               `-su - nobody
  |                   `-sh
  |                       `-emacs /tmp/ee.txt
  |                           `-dbus-launch 
--autolaunch=583e5eeffd5b64952b92010045b373b0 --binary-syntax --close-stderr




-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to