Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 3 Dec 2019 07:12:05 -0800
From: Tavis Ormandy <taviso@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: virtual consoles

On Tue, Dec 03, 2019 at 12:34:14PM +0000, Simon McVittie wrote:
> On Mon, 02 Dec 2019 at 08:56:38 -0800, Tavis Ormandy wrote:
> > unprivileged users can start a new X server and switch virtual
> > console, even over ssh.
> > 
> > e.g.
> > 
> > $ dbus-send --system --print-reply --dest=org.freedesktop.login1 /org/freedesktop/login1/seat/seat0 org.freedesktop.login1.Seat.SwitchTo uint32:2
> 
> If a uid who is not already the owner of the current VT on the seat can
> do this, then that's probably a bug? If you think so, please report it
> to the maintainers of logind (which is the component that would have to
> change to address this).
> 

I sent a mail to the systemd-security list, maybe they'll agree and just
change it.

Tavis.


-- 
-------------------------------------
taviso@....lonestar.org | finger me for my pgp key.
-------------------------------------------------------

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.