Bug#403557: xscreensaver does not lock when there are network problems

2006-12-25 Thread 7nrmi1s02
Steve Langasek vorlon-at-debian.org |bugs-debian| wrote: Because if you're using nss_ldap, a lot more goes wrong than your X session remaining unlocked when the LDAP server disappears; local mail delivery (if any), cronjobs, and many other processes will fail, and things as simple as a directory

Bug#403557: xscreensaver does not lock when there are network problems

2006-12-23 Thread Steve Langasek
On Thu, Dec 21, 2006 at 07:37:27PM +0100, [EMAIL PROTECTED] wrote: > Steve Langasek wrote: > >If the user's account is local, nss should be resolving it before ever > >touching LDAP. If it's remote, provisions should be in place to ensure the > >LDAP server's availability. Either way, I only see

Bug#403557: xscreensaver does not lock when there are network problems

2006-12-21 Thread 7nrmi1s02
Steve Langasek wrote: If the user's account is local, nss should be resolving it before ever touching LDAP. If it's remote, provisions should be in place to ensure the LDAP server's availability. Either way, I only see this security bug happening on a misconfigured system. Why should there be

Bug#403557: xscreensaver does not lock when there are network problems

2006-12-19 Thread Frank Küster
Steve Langasek <[EMAIL PROTECTED]> wrote: > No, a simple "strings" on /usr/bin/xscreensaver would tell you that this is > specific to the user's configuration which does use nss_ldap. Moreover: [...] Ah, okay. I was only concerned about the terse rationale for the downgrading, now we have ample

Bug#403557: xscreensaver does not lock when there are network problems

2006-12-19 Thread Steve Langasek
On Mon, Dec 18, 2006 at 10:45:12AM +0100, Frank Küster wrote: > Thomas Prokosch <[EMAIL PROTECTED]> wrote: > > Package: xscreensaver > > Version: 4.24-5 > > Severity: grave > > Tags: security > > Justification: user security hole > Why have you set the severity of this bug to important? IMHO it

Bug#403557: xscreensaver does not lock when there are network problems

2006-12-18 Thread Frank Küster
Hi Steve, Thomas Prokosch <[EMAIL PROTECTED]> wrote: > Package: xscreensaver > Version: 4.24-5 > Severity: grave > Tags: security > Justification: user security hole Why have you set the severity of this bug to important? IMHO it should be RC, because indeed for a large group of users (those wi

Bug#403557: xscreensaver does not lock when there are network problems

2006-12-17 Thread Thomas Prokosch
Package: xscreensaver Version: 4.24-5 Severity: grave Tags: security Justification: user security hole I do have set up xscreensaver so that it locks the screen after a certain timeout. This is a handy security feature which is the main reason for using the screensaver. However today the screen wa