← Back to team overview

desktop-packages team mailing list archive

[Bug 849027] Re: lightdm does not provide an equivalent to the gdm guest session AppArmor profile

 

This is a major release blocker. We already opened up the guest session
to not require a previous login, so now being able to access other home
directories is a nasty security regression. I'll have a stab at this.

** This bug has been flagged as a security vulnerability

** Changed in: lightdm (Ubuntu Oneiric)
    Milestone: None => ubuntu-11.10

** Changed in: lightdm (Ubuntu Oneiric)
   Importance: High => Critical

** Changed in: lightdm (Ubuntu Oneiric)
       Status: Triaged => In Progress

** Changed in: lightdm (Ubuntu Oneiric)
     Assignee: Robert Ancell (robert-ancell) => Martin Pitt (pitti)

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to lightdm in Ubuntu.
https://bugs.launchpad.net/bugs/849027

Title:
  lightdm does not provide an equivalent to the gdm guest session
  AppArmor profile

Status in “lightdm” package in Ubuntu:
  In Progress
Status in “lightdm” source package in Oneiric:
  In Progress

Bug description:
  In all recent releases of Ubuntu, gdm provided an AppArmor profile for
  /usr/share/gdm/guest-session/Xsession in /etc/apparmor.d/gdm-guest-
  session to confine the guest user. LightDM should do the same.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lightdm/+bug/849027/+subscriptions


References