This bug was fixed in the package lightdm - 1.14.4-0ubuntu1 --------------- lightdm (1.14.4-0ubuntu1) vivid; urgency=medium
* New upstream release: - Handle XDMCP Request packet with no addresses. (LP: #1516831) - Don't start LightDM if the XDMCP server is configured with a key that doesn't exist. (LP: #1517685) - Add IP addresses to XDMCP log messages. - Refactor XDMCP error handling. - Add more tests. -- Robert Ancell <robert.anc...@canonical.com> Fri, 20 Nov 2015 16:01:15 +1300 ** Changed in: lightdm (Ubuntu Vivid) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lightdm in Ubuntu. https://bugs.launchpad.net/bugs/1517685 Title: XDMCP server starts without authentication if configured key does not exist Status in Light Display Manager: Fix Released Status in Light Display Manager 1.10 series: Fix Released Status in Light Display Manager 1.14 series: Fix Released Status in Light Display Manager 1.16 series: Fix Released Status in Light Display Manager 1.2 series: Fix Released Status in lightdm package in Ubuntu: Fix Released Status in lightdm source package in Precise: Confirmed Status in lightdm source package in Trusty: Fix Released Status in lightdm source package in Vivid: Fix Released Status in lightdm source package in Wily: Fix Released Bug description: [Impact] An incorrectly configured XDMCP server will start without authentication instead of disabling XDMCP / stopping LightDM. [Test Case] 1. Set up LightDM to run an XDMCP server using an XDM authentication key, i.e. in lightdm.conf: [XDMCPServer] enabled=true key=key-name 2. Do not create /etc/lightdm/keys.conf or do not define 'key-name' in keys.conf. 3. Start LightDM 4. Connect XDMCP client. Expected result: Either LightDM doesn't start or the XDMCP server doesn't start. Observed result: XDMCP server starts without authentication, any XDMCP client is able to connect. Debug message printed to log warning about missing key, but not easy to spot. [Regression Potential] Low - change is to not start LightDM if this case occurs. This could affect someone who currently has a misconfigured LightDM. In this case a warning message is printed to the log. To manage notifications about this bug go to: https://bugs.launchpad.net/lightdm/+bug/1517685/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp