Bug#576796: xtrlock can be bypassed using TTY's

2010-04-07 Thread tomm smith
On 4/7/10, Nico Golde wrote: > Hey, > * thims [2010-04-07 12:57]: >> Package: xtrlock >> Version: 2.0-12 >> Severity: grave >> Tags: security >> Justification: user security hole >> >> If one attempts to switch to a TTY while xtrlock is running, it allows the >> system to switch to >> specified T

Bug#576796: xtrlock can be bypassed using TTY's

2010-04-07 Thread Nico Golde
Hey, * thims [2010-04-07 12:57]: > Package: xtrlock > Version: 2.0-12 > Severity: grave > Tags: security > Justification: user security hole > > If one attempts to switch to a TTY while xtrlock is running, it allows the > system to switch to > specified TTY where xtrlock can be easily killed wi

Bug#576796: xtrlock can be bypassed using TTY's

2010-04-07 Thread thims
Package: xtrlock Version: 2.0-12 Severity: grave Tags: security Justification: user security hole If one attempts to switch to a TTY while xtrlock is running, it allows the system to switch to specified TTY where xtrlock can be easily killed with "killall xtrlock". I run ratpoison, and executi