Bug#869922: policykit-1: members of group sudo become root with pkexec while ignoring /etc/sudoers

2017-07-27 Thread mviereck
Package: policykit-1 Version: 0.105-18 Severity: grave Tags: security Justification: user security hole Dear Maintainer, If an unprivileged user is member of group sudo, he can achieve unrestricted root privileges with pkexec and his user password (instead of root password). This happens regard

Bug#856662: xorg: starting X within X without specifying -vt destroys current X session

2017-03-03 Thread mviereck
Package: xorg Version: 1:7.7+18 Severity: critical Justification: causes serious data loss Dear Maintainer, Steps to reproduce the error: - start an X session - open a terminal emulator and run X :1 This leads to a blanc black screen (can contain blinking cursor or some login messages). The

Bug#856485: xpra: terminating xpra server destroys current X session

2017-03-01 Thread mviereck
Package: xpra Version: 0.17.6+dfsg-1 Severity: critical Justification: causes serious data loss Dear Maintainer, steps to reproduce: 1. start xpra server xpra start :20 --start-child=xterm --exit-with-children 2. attach to server xpra attach :20 3. terminate xpra server (in this case by closi