Control: found -1 1:1.0.10-1
Control: severity -1 grave

On 2013-12-22 18:49:50 +0100, Yves-Alexis Perez wrote:
> control: reassign -1 xserver-xorg-video-nouveau
> control: forcemerge 700235 -1

The grave severity has been lost in the merge, and I think it should
really be grave, as an external user who has physical access to the
keyboard and screen of the machine (no account needed) can easily
access random data from a user's account (unless the user always
switches off the machine after logging out). This is rather limited,
but important information can be leaked (including confidential
information and passwords -- potentially whatever data displayed
during the session).

-- 
Vincent Lefèvre <[email protected]> - Web: <http://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <http://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]
Archive: http://lists.debian.org/[email protected]

Reply via email to