On Wednesday 19 December 2007 16:35:45 Tollef Fog Heen wrote:
> * Peter Antoniac
> : [EMAIL PROTECTED] /tmp/ume-config-common-0.7 > tail -n 6 debian/postinst
>
> # Ew
> if [ -f /etc/X11/Xwrapper.config ]; then
>     sed -i -e 's/allowed_users=.*/allowed_users=anybody/'
> /etc/X11/Xwrapper.config fi
>
> #DEBHELPER#
>
> : [EMAIL PROTECTED] /tmp/ume-config-common-0.7 >
>
> So if that doesn't hit, for some reason, you've found a bug.

It didn't hit :) so it might be a bug. But even if it is a bug, the problem 
still remains: you have allowed_users=anybody into the Xwrapper.config. If 
you use my patch for the /etc/event.d/session then you we don't need to open 
this security hole in Xwrapper.config...

Cheers,
Peter
-- 
 Peter Antoniac, PhD
 https://launchpad.net/~theseinfeld
 GIT/CS a C+++ UL+++$ w--- PGP++ e++++

-- 
Ubuntu-mobile mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-mobile

Reply via email to