slim gives root access

Bug #829268 reported by Dom Rodriguez
254
Affects Status Importance Assigned to Milestone
slim (Ubuntu)
Fix Released
Undecided
Jamie Strandboge

Bug Description

Hello,

I think that I may have discovered a vulnerability in the

Simple Login Manager (or SLIM), I have checked the

bugs on launchpad and I can't see if this bug is a duplicate.

The vulnerability that i think i've discovered is as follows:

When you are at the logon prompt of SLIM, and you can

type in to the username box 'console' (this would open a

console windows in the top-right hand corner and display

a login prompt), I have found by pressing CTRL+SHIFT

+T, which would usually display a new tab in the terminal,

but in this case, it actually showed a logged in root shell.

I am using Ubuntu 9.10. I haven't been able to see if

SLIM has the same vulnerability in Ubuntu 11.04 as of

yet.

The SLIM version I am using is: 1.3.1-2~kkxfce3

On my machine I just commented out the console line in

the '/etc/slim.conf' to disable the console login shell.

I have enclosed a image (.png) showing the root shell open

on SLIM.

Thanks,

shymega.

Tags: slim
Revision history for this message
Dom Rodriguez (shymega) wrote :
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and reporting a bug. I am unable to reproduce this on Ubuntu 11.04. Ubuntu 9.10 is no longer supported and I encourage you to upgrade to Ubuntu 10.04 LTS. After you do so, can you try to reproduce on 10.04 and report back? Thanks

visibility: private → public
Changed in slim (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
status: New → Incomplete
Revision history for this message
Dom Rodriguez (shymega) wrote :

I've just tried to reproduce the bug on Ubuntu 10.04 LTS.

It seems that the configuration file part where the console gave you root access has been to changed to 'xterm'. This was 'x-terminal-emulator' before.

I also found this on Debian Bugs: (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=536542)

Based on this information, I think this bug should be closed as it appears to be no longer reproducible.

Thanks.

Revision history for this message
Dom Rodriguez (shymega) wrote :

SLIM has had a fix on this problem. Bug doesn't seem to reproduce.

Changed in slim (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.