*** This bug is a security vulnerability *** You have been subscribed to a public security bug by Seth Arnold (seth-arnold):
In minimal clean installation of Ubuntu Desktop 18.04.2 LTS, login password is shown in plaintext in console output after 3rd logout from Gnome. Just start the machine, login and logout from Gnome session for more than tree times and login password (and incorrect login attempts) starts to be shown on console that is briefly visible after logout. See https://www.youtube.com/watch?v=lwzX_4qe8nA&t=89s for demonstration. ProblemType: Bug DistroRelease: Ubuntu 18.04 Package: gdm3 3.28.3-0ubuntu18.04.3 ProcVersionSignature: Ubuntu 4.18.0-15.16~18.04.1-generic 4.18.20 Uname: Linux 4.18.0-15-generic x86_64 ApportVersion: 2.20.9-0ubuntu7.5 Architecture: amd64 CurrentDesktop: ubuntu:GNOME Date: Mon Apr 22 22:14:23 2019 InstallationDate: Installed on 2019-04-22 (0 days ago) InstallationMedia: Ubuntu 18.04.2 LTS "Bionic Beaver" - Release amd64 (20190210) SourcePackage: gdm3 UpgradeStatus: No upgrade log present (probably fresh install) ** Affects: gdm3 (Ubuntu) Importance: Undecided Status: New ** Tags: amd64 apport-bug bionic -- Login password disclosure after 3rd logout https://bugs.launchpad.net/bugs/1825890 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
