X2Go Bug report logs - #287
Linux Mint desktops configured too insecurely for multi-user mode

version graph

Package: x2goserver; Maintainer for x2goserver is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goserver is src:x2goserver.

Reported by: David Fuhrmann <fuhrmann_mail@web.de>

Date: Wed, 7 Aug 2013 05:48:02 UTC

Severity: critical

Tags: confirmed, moreinfo, wontfix

Found in version 4.0.1.6

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #55 received at 287@bugs.x2go.org (full text, mbox, reply):

Received: (at 287) by bugs.x2go.org; 17 Aug 2013 07:03:26 +0000
From david.fuhrmann@gmail.com  Sat Aug 17 09:03:26 2013
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=0.0 required=5.0 tests=FREEMAIL_FROM,T_DKIM_INVALID,
	URIBL_BLOCKED autolearn=ham version=3.3.2
Received: from mail-ea0-f174.google.com (mail-ea0-f174.google.com [209.85.215.174])
	by ymir (Postfix) with ESMTPS id 231F05DA6C
	for <287@bugs.x2go.org>; Sat, 17 Aug 2013 09:03:26 +0200 (CEST)
Received: by mail-ea0-f174.google.com with SMTP id z15so1360385ead.19
        for <287@bugs.x2go.org>; Sat, 17 Aug 2013 00:03:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20120113;
        h=sender:subject:mime-version:content-type:from:in-reply-to:date:cc
         :content-transfer-encoding:message-id:references:to;
        bh=50OWwgH351YqPtQas7Qo6mUe738cvnwHQOaNVZVJp0U=;
        b=WvqpWJLt6K07Hrkfz3rdinGRu8J60zpczGzk8JLuBipvTKHafEfcxqirb9XmmStVBV
         PNOhCLLwfX5cHoN5niAmUOgGFuIJXl3BuemNSz6YUUIorv7zjl4TpdFrMglHNDaTyy1v
         /UtDPLWQY7XYc7TytXIQ3Fj8o4OxScSwtPBkDlcexjtDn+2AEG5lnFJT8CqvAWNZjP4D
         CKOeF1rFqA1Lo3cQQdgarJnHBg2/+Fz6lSzI/Ga/hjGQkx4+QNWU9nHAG998gPkZyfaV
         eoiRyleFT73O5t88QjpxdU/sKaftawshAkBVqjivmgnvLvyDdBeIoTL3VcarP6VSh9ju
         3wTg==
X-Received: by 10.14.176.8 with SMTP id a8mr3124883eem.12.1376723005731;
        Sat, 17 Aug 2013 00:03:25 -0700 (PDT)
Received: from macbook.localdomain (erft-4db7c4d8.pool.mediaWays.net. [77.183.196.216])
        by mx.google.com with ESMTPSA id r48sm1666043eev.14.1969.12.31.16.00.00
        (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
        Sat, 17 Aug 2013 00:03:24 -0700 (PDT)
Sender: David Fuhrmann <david.fuhrmann@gmail.com>
Subject: Re: [X2Go-Dev] Bug#287: x2goserver allows to connect to ALL X server sessions by default
Mime-Version: 1.0 (Mac OS X Mail 6.5 \(1508\))
Content-Type: text/plain; charset=us-ascii
From: David Fuhrmann <fuhrmann_mail@web.de>
X-Priority: 3 (Normal)
In-Reply-To: <16BAD52E-0196-43DC-A0D5-57BB7B844530@web.de>
Date: Sat, 17 Aug 2013 09:03:21 +0200
Cc: 287@bugs.x2go.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <32EA1C31-9067-4862-B5A7-24F6909253B3@web.de>
References: <F7C30D2B-5461-457E-8088-7A0933A86EEF@web.de> <20130807114338.13215dfoanwep8sq@mail.das-netzwerkteam.de> <CANN0FUgL27BfEyQ_=4nLiY56rHjo5fGsf1OyDK47vLb2Gdi+jg@mail.gmail.com> <20130807160258.61246yer4vhkibo2@mail.das-netzwerkteam.de> <7590CCCD-172A-4E9A-BF38-49ADA374C4C1@web.de> <E539B638-2553-426F-9092-54BFB09662EF@web.de> <20130807212225.14293ngtwzvr07sh@mail.das-netzwerkteam.de> <16BAD52E-0196-43DC-A0D5-57BB7B844530@web.de>
To: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
X-Mailer: Apple Mail (2.1508)
Any news regarding this bug?

Am 07.08.2013 um 21:56 schrieb David Fuhrmann <fuhrmann_mail@web.de>:

> 
> Am 07.08.2013 um 21:22 schrieb Mike Gabriel <mike.gabriel@das-netzwerkteam.de>:
> 
>> Hi David,
>> 
>> On Mi 07 Aug 2013 20:10:44 CEST David Fuhrmann wrote:
>> 
>>> To rule out some specific configuration issue in our current system, I installed a fresh linux mint inside a virtual machine and was able to confirm the issues.
>>> 
>>> You should be able to reproduce it easily by doing the same. Choose Linux Mint debian edition, 64 Bit, Mate package and install x2goserver following your instructions for debian 7.
>> 
>> What is the primary GID of users on Linux Mint. Do they follow the pattern
>> 
>> foo:foo
>> bar:bar
>> sunweaver:sunweaver
>> 
>> or is there a group that all users get crushed in with there primary GIDs, like
>> 
>> foo:users
>> bar:users
>> sunweaver:users
> 
> In a fresh linux mint system, the first one. In our production environment, the latter one.


Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Fri Apr 19 09:16:07 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.