← Back to team overview

dx-packages team mailing list archive

[Bug 1447821] [NEW] Lockscreen does not ask for ldap password

 

*** This bug is a security vulnerability ***

You have been subscribed to a public security bug:

I manage desktops where the users log into an today updated ubuntu
14.04.1 amd64 desktop using ldap users.

When the desktop goes to lockscreen, in order to unlock I may [see IMG_20150423_182816.jpg attached]:
1. Use my right ldap password: Unlock successfully;
2. Use a wrong ldap password: It doesn't unlock, showing an error message;
3. Don't use any password, just press "Enter":  Unlock successfully!

This is a serious security failure. One unauthorized person walking
around could access a machine and use it.

There's no references in logs like syslog, auth.log, etc.

** Affects: unity (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: ldap
-- 
Lockscreen does not ask for ldap password
https://bugs.launchpad.net/bugs/1447821
You received this bug notification because you are a member of DX Packages, which is subscribed to unity in Ubuntu.