[Bug 776075] New: Dolphin terminal (console) remembers su (root) login after closing
https://bugzilla.novell.com/show_bug.cgi?id=776075 https://bugzilla.novell.com/show_bug.cgi?id=776075#c0 Summary: Dolphin terminal (console) remembers su (root) login after closing Classification: openSUSE Product: openSUSE 12.1 Version: Final Platform: x86-64 OS/Version: openSUSE 12.1 Status: NEW Severity: Major Priority: P5 - None Component: KDE4 Applications AssignedTo: kde-maintainers@suse.de ReportedBy: me@kalenz.eu QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1 When closing a terminal emulator after switching to su mode (root), the expectation is that su has been logged out. In other words, when the terminal is reopened, it has local user privileges only. Reproducible: Always Steps to Reproduce: 1. Open Dolphin from a local user (non-root) KDE session. 2. Hit F4 to bring up the terminal panel. 3. Write "su" enter, type root password --> gain root privileges. 4. Hit F4 again --> terminal closes. 5. On the same Dolphin window, hit F4 again... Actual Results: ...surprise, you're still root!! Expected Results: Should have lost root privileges after closing the terminal panel. In everyday office work, many Dolphin windows can be open at once, and stay open for days or weeks. Due to this bug, a "hidden" root login can remain active for a long time on machines accessible to many users, and "reappear" when someone just happens to press F4 on the same window. Reporting as "Major" severity due to security concern. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=776075 https://bugzilla.novell.com/show_bug.cgi?id=776075#c1 Christian Trippe <ctrippe@opensuse.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO CC| |ctrippe@opensuse.org InfoProvider| |me@kalenz.eu --- Comment #1 from Christian Trippe <ctrippe@opensuse.org> 2012-09-11 20:17:04 UTC --- The same behaviour is true for 12.2. But I would say that F4 only shows/hides the terminal and does not open/close it. For me personally that is the expected behaviour, But I get your point. However this is something upstream has to change. So if you really feel this should be "fixed" please report it upstream at bugs.kde.org. Would this be ok for you? -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=776075 https://bugzilla.novell.com/show_bug.cgi?id=776075#c2 Christian Trippe <ctrippe@opensuse.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |RESOLVED InfoProvider|me@kalenz.eu | Resolution| |WORKSFORME --- Comment #2 from Christian Trippe <ctrippe@opensuse.org> 2012-10-16 19:10:09 UTC --- Closing as worksforme. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=776075 https://bugzilla.novell.com/show_bug.cgi?id=776075#c Kalenz . <me@kalenz.eu> changed: What |Removed |Added ---------------------------------------------------------------------------- Component|KDE4 Applications |KDE4 Applications See Also| |https://bugs.kde.org/show_b | |ug.cgi?id=309378 Product|openSUSE 12.1 |openSUSE 12.2 OS/Version|openSUSE 12.1 |openSUSE 12.2 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=776075 https://bugzilla.novell.com/show_bug.cgi?id=776075#c3 --- Comment #3 from Kalenz . <me@kalenz.eu> 2012-11-01 15:20:15 UTC --- Posted to bugs.kde.org. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com