Summary: | World-readable X11 Cookie, easy key logger | ||
---|---|---|---|
Product: | [I don't know] kde | Reporter: | David Rumley <Davidl.Rumley> |
Component: | general | Assignee: | Unassigned bugs mailing-list <unassigned-bugs> |
Status: | RESOLVED DUPLICATE | ||
Severity: | normal | CC: | aacid, cfeck, kensington, mbriza, pierluigi.fiorini, security |
Priority: | NOR | ||
Version: | unspecified | ||
Target Milestone: | --- | ||
Platform: | Arch Linux | ||
OS: | Linux | ||
Latest Commit: | Version Fixed In: |
Description
David Rumley
2016-05-16 15:55:02 UTC
www.kde.org might be the wrong Product, no? Not sure where it would belong to, though. Maybe frameworks-kinit? I'm not sure, I thought it belonged here. If not I can always move it. I'd say this is a bug in sddm. Abusing the CC here to add Pier Luigi and Martin for confirmation. Moving to a generic component to get this off the kde-www mailing list. Bug 329616 indicates that the xauth file might not be created by the display manager. *** This bug has been marked as a duplicate of bug 358593 *** That bug is only for the tmp file for not for .Xauthority ? sddm creates ~/.Xauthority with xauth, but you are talking of another file here. this indeed might be a duplicate of 358593 as it sounds a lot like the file referenced there. Right i read the code of sddm too quickly and thought it was using a QFile to create the .XAuthority file. *** This bug has been marked as a duplicate of bug 358593 *** sddm should set the XAUTHORITY env var, you might consider changing kdeinit to use that instead |