Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-06-09 Thread Jim Scadden
On Thu, Jun 05, 2014 at 10:52:54AM +0200, Lajos Mester wrote: I tried to log in a diffrerent order, and came out, that it wasn't the number of the VT-s, but allways the same user who got logged in without a valid password. I have no idea why this happened. And I'm unable to reproduce it

Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-06-03 Thread Jim Scadden
On Fri, May 30, 2014 at 09:03:01PM +0200, Lajos Mester wrote: This looks like the authentication is actually passing. Could you try installing pamtester (which is availale for jessie/sid) and run the following command and provide the results: pamtester -v login username authenticate

Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-05-30 Thread Lajos Mester
Am Donnerstag, 29. Mai 2014, 21:47:29 schrieben Sie: On Tue, May 27, 2014 at 06:50:01PM +0200, Lajos Mester wrote: * What authentication type is PAM using (e.g. shadow, ldap, krb5) ? How do I know it? Unless you have changed it, the default should be shadow. Documentation for PAM is

Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-05-29 Thread Jim Scadden
On Tue, May 27, 2014 at 06:50:01PM +0200, Lajos Mester wrote: * What authentication type is PAM using (e.g. shadow, ldap, krb5) ? How do I know it? Unless you have changed it, the default should be shadow. Documentation for PAM is available at http://www.linux-pam.org/ * What is the result

Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-05-27 Thread Lajos Mester
Hi Jim, thanks for careing... i have testing-unstable installed, almost always up to date. The bug is still there. Please find the anwers to your questions below. If you need more info, just drop a mail. Thanks and regards. Lajos Am Sonntag, 25. Mai 2014, 08:32:18 schrieben Sie: tags

Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-05-25 Thread Jim Scadden
tags 737396 + moreinfo stop Hi Lajos, I have been unable to reproduce this bug with the current versions of kscreensaver in wheezy (4:4.8.4-5) and jessie (4:4.12.4-1). Please could you advise the following to help reproduce the problem: * Are all of VT sessions logged in as different users? *

Bug#737396: kscreensaver: locked screen allows any password if a third session (vt9) is also active

2014-02-02 Thread Lajos Mester
Package: kscreensaver Version: 4:4.8.4-5 Justification: causes serious data loss Severity: critical Tags: security Dear Maintainer, after activating tree (kde-)sessions on vt7,vt8 and vt9, one of the sessions does not need having a password entered at the login widget, still, it lets