Your message dated Fri, 16 Oct 2009 04:17:48 +0000
with message-id <e1myegc-0005cb...@ries.debian.org>
and subject line Bug#536542: fixed in slim 1.3.1-2
has caused the Debian Bug report #536542,
regarding slim: allows login as root without password
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
536542: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=536542
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: slim
Version: 1.3.0-2
Severity: grave
Tags: security
Justification: user security hole
X-Debbugs-Cc: t...@security.debian.org

Typing 'console' in the SLiM login prompt opens a gnome terminal running
login(1). Opening a new terminal from the terminal menu (File -> Open
Terminal) opens a gnome terminal running a root shell.


-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (500, 'testing'), (400, 'unstable'), (300, 'experimental')
Architecture: i386 (x86_64)

Kernel: Linux 2.6.30 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages slim depends on:
ii  debconf [debconf-2.0]         1.5.26     Debian configuration management sy
ii  libc6                         2.9-12     GNU C Library: Shared libraries
ii  libgcc1                       1:4.4.0-5  GCC support library
ii  libjpeg62                     6b-14      The Independent JPEG Group's JPEG
ii  libpam0g                      1.0.1-9    Pluggable Authentication Modules l
ii  libpng12-0                    1.2.37-1   PNG library - runtime
ii  libstdc++6                    4.4.0-5    The GNU Standard C++ Library v3
ii  libx11-6                      2:1.2.1-1  X11 client-side library
ii  libxft2                       2.1.13-3   FreeType-based font drawing librar
ii  libxmu6                       2:1.0.4-1  X11 miscellaneous utility library

Versions of packages slim recommends:
ii  gnome-terminal [x-terminal-em 2.26.2-2   The GNOME terminal emulator applic

Versions of packages slim suggests:
pn  scrot                         <none>     (no description available)

-- debconf information excluded



--- End Message ---
--- Begin Message ---
Source: slim
Source-Version: 1.3.1-2

We believe that the bug you reported is fixed in the latest version of
slim, which is due to be installed in the Debian FTP archive:

slim_1.3.1-2.diff.gz
  to pool/main/s/slim/slim_1.3.1-2.diff.gz
slim_1.3.1-2.dsc
  to pool/main/s/slim/slim_1.3.1-2.dsc
slim_1.3.1-2_i386.deb
  to pool/main/s/slim/slim_1.3.1-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 536...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Nobuhiro Iwamatsu <iwama...@debian.org> (supplier of updated slim package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 21 Sep 2009 15:52:33 +0900
Source: slim
Binary: slim
Architecture: source i386
Version: 1.3.1-2
Distribution: unstable
Urgency: low
Maintainer: Nobuhiro Iwamatsu <iwama...@debian.org>
Changed-By: Nobuhiro Iwamatsu <iwama...@debian.org>
Description: 
 slim       - desktop-independent graphical login manager for X11
Closes: 505332 510469 529306 536542
Changes: 
 slim (1.3.1-2) unstable; urgency=low
 .
   * Add Jens Peter Secher to Uploaders list.
   * Update es.po (Closes: #510469)
   * Fix FTBFS with GCC 4.4. (Closes: #505332)
   * Fix insecure xauth secret. (Closes: #529306)
   * Fix allows login as root without password. (Closes: #536542)
      - Wrote explanation about this problem to README.Debian.
Checksums-Sha1: 
 5119604aacafbdaa7262c6354ea393c2ac9e0d74 1116 slim_1.3.1-2.dsc
 ed59be2979a66da6991f6845f5a3139428423ca3 661700 slim_1.3.1-2.diff.gz
 cd3bccc47f109c65e5b8332c968949be73328a45 817378 slim_1.3.1-2_i386.deb
Checksums-Sha256: 
 05bc56c6e0b8b1f7885528db5c95ce1eaf8a126a2d3ab64b82c0e0619124bf89 1116 
slim_1.3.1-2.dsc
 dec450826bf00393f7a4e5ddab0266c33bdec1b4340c886e1d6cd6b44d74d6a5 661700 
slim_1.3.1-2.diff.gz
 731d0ec9702594dd51154957b542a38896c4ee92cf36c8f98260751557b8edbf 817378 
slim_1.3.1-2_i386.deb
Files: 
 6a2e27f370abb242163e3c2b10ddc266 1116 x11 optional slim_1.3.1-2.dsc
 1feb39759d74b09e4823008f549573a6 661700 x11 optional slim_1.3.1-2.diff.gz
 38f1310801713ba27b9cf03dce0385ea 817378 x11 optional slim_1.3.1-2_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkrX7qUACgkQQSHHQzFw6+npRQCfeL+5qMhjIkD/J0lG0cNoLpzc
yDgAnigOADGH0YOhAkGVfylIGGcmWET8
=RjkV
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to