There may also exist a security issue, where user alice creates
specially crafted keymaps in /tmp/$HASH.xkm and then user bob launched X
and the X system tries to re-use alice's evil keymap.

I'm unsure if the X server keymap loader is exploitable, but it is
likely that keymaps should not be shared between users in this way (if
nothing else, alice can upload a wacky keymap and bob may not know how
to turn it off.)

-A

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/972324

Title:
  server fails to start up if TMPDIR is set to something on a different
  filesystem from /var/lib/xkb

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/972324/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to