*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

Corrected copy and pasted info Nov. 17th.

If written quickly after a failed attempt xfce4-terminal shows password
visibly in actual characters and accepts the password.

Example (the word "pass" is the password):


brett@BrettPC:~$ sudo su
[sudo] password for brett:
pass
Sorry, try again.
[sudo] password for brett:
root@BrettPC:/home/brett#

To clarify I did not enter a password the second time it sad "[sudo]
password for brett:" it simply accepted the one shown visibly.

** Affects: xfce4-terminal (Ubuntu)
     Importance: Undecided
     Assignee: Andrew Donald (senoir-cielo)
         Status: New

-- 
xfce4-terminal shows password visibly in clear between attempts and accepts 
(updated Nov. 17th)
https://bugs.launchpad.net/bugs/1641259
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to