Bug#954094: /bin/systemd: Running startx in X session switches to VC, input duplicated to X, login at getty exfiltrates creds

2020-03-16 Thread Michael Biebl
Control: forcemerge 929116 -1 Looks like a duplicate of https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929116 so merging accordingly. signature.asc Description: OpenPGP digital signature

Bug#954094: /bin/systemd: Running startx in X session switches to VC, input duplicated to X, login at getty exfiltrates creds

2020-03-16 Thread Justus Winter
Package: systemd Version: 241-7~deb10u3 Severity: critical File: /bin/systemd Tags: security Justification: root security hole Dear Maintainer, I was trying to spawn an Xephyr server using startx, but messed up the arguments (I can reproduce it by simply running 'startx'). My X session