Comment 7 for bug 310126

Revision history for this message
Anders Kaseorg (andersk) wrote : Re: failsafeXinit: launches gnome-terminal or gedit as root without a password

This vulnerability has not gone away; failsafeXinit still allows an untrusted user to run gedit as root. I don’t have an ultimate solution, but removing the three vulnerable options would be a good first step. We could then open up this bug (or a new bug) so that other contributors can figure out how to add back this functionality in a secure way.