.Xauthority.****** files polluting $Home

Bug #1175023 reported by Debabrata Das on 2013-05-01
178
This bug affects 38 people
Affects Status Importance Assigned to Milestone
lightdm (Ubuntu)
Medium
Unassigned
Raring
Undecided
Marc Deslauriers
Saucy
Medium
Unassigned

Bug Description

.Xauthority.****** files polluting $Home. Where '*'s are random capital alphabets and numbers of exactly 6 charater length. In Ubuntu 12.04 it was '.goutputstream' polluting $HOME, so may be it's some how related to bug 984785.

ProblemType: Bug
DistroRelease: Ubuntu 13.04
Uname: Linux 3.8.0-19-generic
Architecture: i386, amd64
Date: Wed May 1 08:45:31 2013
InstallationMedia: Ubuntu 13.04 i386, Ubuntu 13.04 amd64
UpgradeStatus: No upgrade ( fresh install)

CVE References

Thank you for taking the time to report this bug and helping to make Ubuntu better. It seems that your bug report is not filed about a specific source package though, rather it is just filed against Ubuntu in general. It is important that bug reports be filed about source packages so that people interested in the package can find the bugs about it. You can find some hints about determining what package your bug might be about at https://wiki.ubuntu.com/Bugs/FindRightPackage. You might also ask for help in the #ubuntu-bugs irc channel on Freenode.

To change the source package that this bug is filed about visit https://bugs.launchpad.net/ubuntu/+bug/1175023/+editstatus and add the package name in the text box next to the word Package.

[This is an automated message. I apologize if it reached you inappropriately; please just reply to this message indicating so.]

tags: added: bot-comment
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in ubuntu:
status: New → Confirmed
affects: ubuntu → lightdm (Ubuntu)
John Clark (clarkjc) wrote :

I can confirm this bug in 13.04. Also, the .Xauthority file is created with permissions of 0664 instead of the secure 0600.

Doug McMahon (mc3man) on 2013-06-08
tags: added: raring saucy
Mike (mrmikee) wrote :

Same trouble here.

Win7(Host) running VirtualBox 4.2.16
Linux Mint 14 Nadia Kernel 3.5.0-17-generic(i686) (Guest)(Yes, not Ubuntu, but based on same code)

Guest applications Geany(1.22), Pluma(1.4.0), and Gedit (2.30.4) cannot save to existing file.
Must create new file for each save on the Vbox shared folder. Other local(guest) folders work fine.

Did not start until Virtualbox updated to 4.2.16 no problems with setup before that.

Attempting to save an existing file with modifications results in files with names like (.goutputstream-0ZD71W) etc. and warnings that the file may have been truncated.

Two solutions I have found so far are:
1.) save-as a new file name each time I make a change. (terrible)
2.) open a terminal session in that folder and use nano or vi to edit text file. (no problems)

So it seems that the drive "mount" for the shared folder is ok as nano can edit files, but the "gui apps" have an issue.

Robert Ancell (robert-ancell) wrote :

It is basically the same issue in bug 984785 and should be fixed in lightdm 1.4.2, 1.6.1 and 1.7.1

Changed in lightdm (Ubuntu):
status: Confirmed → Fix Released
importance: Undecided → Medium
Changed in lightdm (Ubuntu Raring):
status: New → Confirmed
assignee: nobody → Marc Deslauriers (mdeslaur)
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package lightdm - 1.6.0-0ubuntu3.1

---------------
lightdm (1.6.0-0ubuntu3.1) raring-security; urgency=low

  * SECURITY UPDATE: wrong permissions on .Xauthority file (LP: #1175023)
    - debian/patches/07_xauthority_perms.patch: use g_open instead of
      g_file_set_contents in src/xauthority.c.
    - debian/patches/08_xauthority_fix_perms.patch: fix incorrect
      permissions left behind by previous versions in src/xauthority.c.
    - CVE-2013-4331
 -- Marc Deslauriers <email address hidden> Thu, 12 Sep 2013 08:00:21 -0400

Changed in lightdm (Ubuntu Raring):
status: Confirmed → Fix Released
Sadi Yumuşak (sa-yu) wrote :

Unfortunately this still affects me after upgrading lightdm to 1.6.0-0ubuntu3.1

dskecse (dskecse) on 2014-03-25
description: updated
bryncoles (brunomatti) wrote :

Still affected with lightdm 1.10.1 in Xubuhtu 14:4 (upgraded form 13:10).

Marc Deslauriers (mdeslaur) wrote :

@bryncoles: this bug is fixed. Are you sure those files are recent? what are the dates on them?

To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers