Bug#678951: [Tts-project] Bug#678951: speech-dispatcher user should not have a valid shell
tag 678951 + pending thanks On Sat, Apr 02, 2016 at 10:41:43PM AEDT, Nicolas LE CAM wrote: > Package: speech-dispatcher > Followup-For: Bug #678951 > Control: found > > Dear Maintainer, > > I did saw the same exact problem while checking my passwd file on a fresh > install and was going to report it. > As it was marked resolved I've upgraded to 0.8.3-1/experimental but the > problem persists. > > Looking to the git repo, I saw that the useradd command is only executed if > the user doesn't exists. > Perhaps add a "usermod --shell /bin/false $USER_NAME" in the other case to > fix the problem for everyone. Thanks for the suggestion, added to git, will go in with the next upload. Luke
Bug#678951: speech-dispatcher user should not have a valid shell
Package: speech-dispatcher Followup-For: Bug #678951 Control: found Dear Maintainer, I did saw the same exact problem while checking my passwd file on a fresh install and was going to report it. As it was marked resolved I've upgraded to 0.8.3-1/experimental but the problem persists. Looking to the git repo, I saw that the useradd command is only executed if the user doesn't exists. Perhaps add a "usermod --shell /bin/false $USER_NAME" in the other case to fix the problem for everyone. regards, Nicolas -- System Information: Debian Release: stretch/sid APT prefers testing APT policy: (1000, 'testing'), (900, 'testing'), (50, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Kernel: Linux 4.5.0-trunk-amd64 (SMP w/4 CPU cores) Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages speech-dispatcher depends on: ii adduser 3.114 ii libc62.22-4 ii libdotconf0 1.3-0.2 ii libespeak1 1.48.04+dfsg-2 ii libflite12.0.0-release-1 ii libglib2.0-0 2.48.0-1 ii libltdl7 2.4.6-0.1 ii libsndfile1 1.0.25-10 ii libspeechd2 0.8-7 ii lsb-base 9.20160110 ii speech-dispatcher-audio-plugins 0.8.3-1 speech-dispatcher recommends no packages. Versions of packages speech-dispatcher suggests: pn libttspico-utils pn speech-dispatcher-doc-cs pn speech-dispatcher-festival -- no debconf information
Bug#678951: speech-dispatcher user should not have a valid shell
Package: speech-dispatcher Version: 0.7.1-6.1 Severity: normal Dear Maintainer, Tiger 1:3.2.3-10 reports that the speeach-dispatcher user is disabled but still has a valid shell: --- NEW: --WARN-- [pass014w] Login (speech-dispatcher) is disabled, but has a valid shell. --- Looking at my /etc/passwd file, normally disabled accounts have something such as /bin/false as their shell, thus further preventing an attacker from logging into that account. See /usr/lib/tiger/scripts/check_passwd for the location of this check. -- System Information: Debian Release: wheezy/sid APT prefers testing APT policy: (500, 'testing'), (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 3.2.0-2-amd64 (SMP w/4 CPU cores) Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages speech-dispatcher depends on: ii adduser3.113+nmu3 ii dpkg 1.16.3 ii install-info 4.13a.dfsg.1-10 ii libao4 1.1.0-2 ii libasound2 1.0.25-3 ii libaudio2 1.9.3-5 ii libc6 2.13-33 ii libdotconf1.0 1.0.13-3 ii libespeak1 1.46.02-2 ii libflite1 1.4-release-5 ii libglib2.0-0 2.32.3-1 ii libpulse0 2.0-3 ii libspeechd20.7.1-6.1 ii lsb-base 4.1+Debian6 Versions of packages speech-dispatcher recommends: ii pulseaudio 2.0-3 Versions of packages speech-dispatcher suggests: pn libttspico-utils pn speech-dispatcher-doc-cs pn speech-dispatcher-festival -- no debconf information -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org