desktop-packages team mailing list archive
-
desktop-packages team
-
Mailing list archive
-
Message #26237
[Bug 849027] Re: lightdm does not provide an equivalent to the gdm guest session AppArmor profile
This is a major release blocker. We already opened up the guest session
to not require a previous login, so now being able to access other home
directories is a nasty security regression. I'll have a stab at this.
** This bug has been flagged as a security vulnerability
** Changed in: lightdm (Ubuntu Oneiric)
Milestone: None => ubuntu-11.10
** Changed in: lightdm (Ubuntu Oneiric)
Importance: High => Critical
** Changed in: lightdm (Ubuntu Oneiric)
Status: Triaged => In Progress
** Changed in: lightdm (Ubuntu Oneiric)
Assignee: Robert Ancell (robert-ancell) => Martin Pitt (pitti)
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to lightdm in Ubuntu.
https://bugs.launchpad.net/bugs/849027
Title:
lightdm does not provide an equivalent to the gdm guest session
AppArmor profile
Status in “lightdm” package in Ubuntu:
In Progress
Status in “lightdm” source package in Oneiric:
In Progress
Bug description:
In all recent releases of Ubuntu, gdm provided an AppArmor profile for
/usr/share/gdm/guest-session/Xsession in /etc/apparmor.d/gdm-guest-
session to confine the guest user. LightDM should do the same.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lightdm/+bug/849027/+subscriptions
References