Login password disclosure after 3rd logout

Bug #1825890 reported by Petr Svoboda
This bug report is a duplicate of:  Bug #1803993: Password appears on the VT1 screen. Edit Remove
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gdm3 (Ubuntu)
New
Undecided
Unassigned
plymouth (Ubuntu)
New
Undecided
Unassigned

Bug Description

In minimal clean installation of Ubuntu Desktop 18.04.2 LTS, login password is shown in plaintext in console output after 3rd logout from Gnome. Just start the machine, login and logout from Gnome session for more than tree times and login password (and incorrect login attempts) starts to be shown on console that is briefly visible after logout. See https://www.youtube.com/watch?v=lwzX_4qe8nA&t=89s for demonstration.

ProblemType: Bug
DistroRelease: Ubuntu 18.04
Package: gdm3 3.28.3-0ubuntu18.04.3
ProcVersionSignature: Ubuntu 4.18.0-15.16~18.04.1-generic 4.18.20
Uname: Linux 4.18.0-15-generic x86_64
ApportVersion: 2.20.9-0ubuntu7.5
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
Date: Mon Apr 22 22:14:23 2019
InstallationDate: Installed on 2019-04-22 (0 days ago)
InstallationMedia: Ubuntu 18.04.2 LTS "Bionic Beaver" - Release amd64 (20190210)
SourcePackage: gdm3
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Petr Svoboda (pbdname) wrote :
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Does this still happen after updating?

Thanks

information type: Private Security → Public Security
Revision history for this message
Petr Svoboda (pbdname) wrote :

After sudo apt update && sudo apt upgrade? Yes.

Revision history for this message
Seth Arnold (seth-arnold) wrote :
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1803993, so it is being marked as such. Please look at the other bug report to see if there is any missing information that you can provide, or to see if there is a workaround for the bug. Additionally, any further discussion regarding the bug should occur in the other report. Feel free to continue to report any other bugs you may find.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.