[Bug 220268] New: KDM allows EVERYBODY to shutdown/reboot via VNC Remote Administration on 5900
https://bugzilla.novell.com/show_bug.cgi?id=220268 Summary: KDM allows EVERYBODY to shutdown/reboot via VNC Remote Administration on 5900 Product: openSUSE 10.2 Version: Beta 2 Platform: i686 OS/Version: Other Status: NEW Severity: Critical Priority: P5 - None Component: KDE AssignedTo: kde-maintainers@suse.de ReportedBy: danielstefanmader@web.de QAContact: qa@suse.de As already reported for 10.1, it is still possible to shutdown/reboot the machine remotely via VNC on port 5900 ("Remote Administration") without any authentication at all. Checking KDM's default settings for shutdown it says Local: Everybody Remote: Only Root This is an enormous security issue since the root-password should be requested for such activity! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=220268 ------- Comment #1 from danielstefanmader@web.de 2006-11-12 08:00 MST ------- Setting the KDM shutdown behavior to Nobody could be a first workaround! I just tried it and this works as expected. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=220268 dmueller@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|kde-maintainers@suse.de |coolo@novell.com -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=220268 coolo@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |ASSIGNED ------- Comment #2 from coolo@novell.com 2006-11-16 09:45 MST ------- can reproduce it -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
https://bugzilla.novell.com/show_bug.cgi?id=220268 coolo@novell.com changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |RESOLVED Resolution| |FIXED ------- Comment #3 from coolo@novell.com 2006-11-16 10:05 MST ------- Lubos will submit my fix. I hope your 10.1 reference is about the build service package -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.
participants (1)
-
bugzilla_noreply@novell.com