Re: [OpenIndiana-discuss] [SECURITY] Security issue in lightdm

2017-05-13 Thread Nikola M
On 05/13/17 09:38 PM, Jim Klimov wrote: > >> I like to put it there IF I set up my workstation laptop installation, >> but it should not be there by default in the first place. (First log >> in, >> identify and IF having rights, can do power actions on machine). >> >> I have a SunRay2 and could try

Re: [OpenIndiana-discuss] [SECURITY] Security issue in lightdm

2017-05-13 Thread Jim Klimov
On May 11, 2017 8:19:12 AM GMT+03:00, Nikola M wrote: >On 05/10/17 04:58 PM, Alexander Pyhalov wrote: >> Hello, guys, I have bad news. >> >> We've found that if VNC or XDMCP access was enabled in lightdm, >remote >> unauthorized user could shutdown or reboot system. The issue was >fixed >> in >> >

Re: [OpenIndiana-discuss] [SECURITY] Security issue in lightdm

2017-05-10 Thread Nikola M
On 05/10/17 04:58 PM, Alexander Pyhalov wrote: > Hello, guys, I have bad news. > > We've found that if VNC or XDMCP access was enabled in lightdm, remote > unauthorized user could shutdown or reboot system. The issue was fixed > in > https://github.com/OpenIndiana/oi-userland/commit/97177ec9190d6e8

[OpenIndiana-discuss] [SECURITY] Security issue in lightdm

2017-05-10 Thread Alexander Pyhalov
Hello, guys, I have bad news. We've found that if VNC or XDMCP access was enabled in lightdm, remote unauthorized user could shutdown or reboot system. The issue was fixed in https://github.com/OpenIndiana/oi-userland/commit/97177ec9190d6e81c6bc6dd7ae8e2c3835044e8c (system/display-manager/lig