Bug#495806: [Secure-testing-team] Bug#495806: Locked screen accepts any password to unlock

2008-08-20 Thread Julien Cristau
On Wed, Aug 20, 2008 at 20:03:47 +0200, Nico Golde wrote: > [EMAIL PROTECTED]:/tmp$] cp /usr/share/doc/libpam0g-dev/examples/check_user.c > . > [EMAIL PROTECTED]:/tmp$] gcc -lpam -lpam_misc check_user.c -o check_user > [EMAIL PROTECTED]:/tmp$] ./check_user nion; date; tail -1 /var/log/kern.log >

Bug#495806: [Secure-testing-team] Bug#495806: Locked screen accepts any password to unlock

2008-08-20 Thread Nico Golde
reassign 495806 pam retitle segfault in pam_unix.so on pam_authenticate call thanks Hi Steve, * Steve Langasek <[EMAIL PROTECTED]> [2008-08-20 19:53]: > On Wed, Aug 20, 2008 at 10:13:25AM -0500, Troy Davis wrote: [...] > > Screen has started accepting any password at all at the locked screen prom

Bug#495806: [Secure-testing-team] Bug#495806: Locked screen accepts any password to unlock

2008-08-20 Thread Steve Langasek
On Wed, Aug 20, 2008 at 10:13:25AM -0500, Troy Davis wrote: > Package: screen > Version: 4.0.3-11 > Severity: grave > Tags: security > Justification: user security hole > Screen has started accepting any password at all at the locked screen prompt > on my testing box. I do not know when exactly t

Bug#495806: Locked screen accepts any password to unlock

2008-08-20 Thread Troy Davis
On Wed, Aug 20, 2008 at 05:26:27PM +0200, Jan Christoph Nordholz wrote: > You are referring to the password prompt that screen shows upon resumption > of a screen session that has been locked with the 'lockscreen' command, > right? I press ^A-x and see: ---snip--- Screen used by Troy Davis

Bug#495806: Locked screen accepts any password to unlock

2008-08-20 Thread Jan Christoph Nordholz
tags 495806 + unreproducible thankyou Hi Troy, I can't reproduce the problem, no matter which PAM version I have installed (0.99.7 or 1.0.1). You are referring to the password prompt that screen shows upon resumption of a screen session that has been locked with the 'lockscreen' command, right?

Bug#495806: Locked screen accepts any password to unlock

2008-08-20 Thread Troy Davis
Package: screen Version: 4.0.3-11 Severity: grave Tags: security Justification: user security hole Hello, Screen has started accepting any password at all at the locked screen prompt on my testing box. I do not know when exactly this behavior started; I just noticed it today. A different box ru