using sudo in "Run Application" (Alt+F2) does not prompt for password

Bug #237803 reported by John Koelndorfer
256
Affects Status Importance Assigned to Milestone
gnome-panel (Ubuntu)
Invalid
Low
Ubuntu Desktop Bugs

Bug Description

Binary package hint: gnome

I saw that this bug was previously invalidated, but it IS a valid bug.

When using Run Application (Alt+F2) you can run commands with sudo using no password. I have used sudo -k and sudo -K to try and clear sudo timestamp, and I can STILL sudo using Alt+F2 without a password.

Even after logging out (by changing runlevel), logging back in, and then trying it without any previous sudos, it still works. This is in 8.04 Hardy Heron, by the way. Gnome version is 2.20.2.2.

Here is a step by step of what I did:

Sudoed in the terminal - but it hadn't been for a long while. The timestamp was probably expired.
By mistake, I hit Alt+F2. I wanted to switch to runlevel 1 to install some NVIDIA drivers. In the run dialog, I typed sudo init 1.
System dropped to runlevel 1 without asking for a password.
I installed drivers, ran init 5 at the root terminal.
Logged back in, DID NOT USE SUDO, and, as a test, ran a sudo command in the run dialog (Alt+F2). I actually used sudo nautilus, which, as I thought, opened nautilus which defaulted to root's home and once again did not ask for a password.

To test this further, I logged out yet again, logged back in, ran sudo -k and sudo -K to try and kill sudo entirely, and I was still allowed to sudo via Alt+F2. Fortunately, I discovered that this did not occur on my laptop, also running 8.04, on a cold boot.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

I am not able to reproduce this on up to date Hardy.

Revision history for this message
Pedro Villavicencio (pedro) wrote :

Thanks for the report, May you tell us a few easy steps in order to reproduce this bug with a clean user profile? thanks.

Changed in gnome-panel:
assignee: nobody → desktop-bugs
importance: Undecided → Low
status: New → Incomplete
Revision history for this message
Pedro Villavicencio (pedro) wrote :

We are closing this bug report because it lacks the information we need to investigate the problem, as described in the previous comments. Please reopen it if you can give us the missing information, and don't hesitate to submit bug reports in the future. To reopen the bug report you can click on the current status, under the Status column, and change the Status back to "New". Thanks again!.

Changed in gnome-panel:
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.