settings allow arbitrarily large user pictures which makes the user lock themselves out at lightdm.

Bug #1512963 reported by Lyn Perrine
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
LightDM GTK Greeter
Fix Released
Undecided
Unassigned
lightdm-gtk-greeter (Ubuntu)
Fix Released
Critical
Unassigned

Bug Description

To reproduce on a fresh install of ubuntu mate 16.04 start lightdm-gtk-greeter-settings and authenticate to start editing lightdm settings. Please do not try to reproduce this on a production machine as it will involve locking yourself out of lightdm.

In the settings for lightdm GTK+ greeter settings select a really large image from a digial camera or high resolution screenshot as your user image that is larger than your screen resolution hit save and then log out.

You will be taken to a lightdm screen that has a user image so large you cannot login.

Description: Ubuntu Xenial Xerus (development branch)
Release: 16.04
lightdm-gtk-greeter-settings:
  Installed: 1.2.0-0ubuntu1
  Candidate: 1.2.0-0ubuntu1
  Version table:
 *** 1.2.0-0ubuntu1 0
        500 http://us.archive.ubuntu.com/ubuntu/ xenial/universe amd64 Packages
        100 /var/lib/dpkg/status

I would expect the greeter to check that it would not set such redicolous file sizes that block the user from logging in or at least provide a warning dialog that this could make you unable to login similar to things that cause data loss on a partition in ubuquity or gparted.

As this prevents even loggin into guest session graphically. I did manage to get back in editing /etc/lightdm/lightdm-gtk-greeter.conf by hand with vim.

ProblemType: Bug
DistroRelease: Ubuntu 16.04
Package: lightdm-gtk-greeter-settings 1.2.0-0ubuntu1
ProcVersionSignature: Ubuntu 4.2.0-16.19-generic 4.2.3
Uname: Linux 4.2.0-16-generic x86_64
ApportVersion: 2.19.2-0ubuntu1
Architecture: amd64
CurrentDesktop: MATE
Date: Tue Nov 3 22:51:13 2015
InstallationDate: Installed on 2015-11-03 (0 days ago)
InstallationMedia: Ubuntu-MATE 16.04 LTS "Xenial Xerus" - Alpha amd64 (20151103)
PackageArchitecture: all
SourcePackage: lightdm-gtk-greeter-settings
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Lyn Perrine (walterorlin) wrote :
Revision history for this message
Lyn Perrine (walterorlin) wrote :
James Lu (jlu5)
summary: - settings allow arbitarly large user pictures which makes the user lock
+ settings allow arbitrarily large user pictures which makes the user lock
themselves out at lightdm.
Revision history for this message
finny388 (alteahandle-launchpad) wrote :

Ubuntu Mate 16.04
Same here. Workaround: Tab 3 times, enter pw, Enter.

Pretty lame.

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in lightdm-gtk-greeter-settings (Ubuntu):
status: New → Confirmed
Changed in lightdm-gtk-greeter-settings (Ubuntu):
importance: Undecided → Critical
Changed in lightdm-gtk-greeter-settings:
status: New → Confirmed
description: updated
Revision history for this message
James Lu (jlu5) wrote :

Is there any specific limit on the largest file size / resolution LightDM GTK+ Greeter supports?

Revision history for this message
Sean Davis (bluesabre) wrote :

Resolved with this commit. User images provided by AccountsService were scaled while default images were not.
http://bazaar.launchpad.net/~lightdm-gtk-greeter-team/lightdm-gtk-greeter/trunk/revision/366

Changed in lightdm-gtk-greeter-settings:
status: Confirmed → Invalid
Changed in lightdm-gtk-greeter:
status: New → Fix Committed
no longer affects: lightdm-gtk-greeter-settings
no longer affects: lightdm-gtk-greeter-settings (Ubuntu)
Changed in lightdm-gtk-greeter (Ubuntu):
status: New → Confirmed
importance: Undecided → Critical
Sean Davis (bluesabre)
Changed in lightdm-gtk-greeter:
milestone: none → 2.0.3
status: Fix Committed → Fix Released
Sean Davis (bluesabre)
Changed in lightdm-gtk-greeter (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.