From owner-freebsd-security Sun Dec 16 14:47:45 2001 Delivered-To: freebsd-security@freebsd.org Received: from excalibur.skynet.be (excalibur.skynet.be [195.238.3.135]) by hub.freebsd.org (Postfix) with ESMTP id 1724137B417 for ; Sun, 16 Dec 2001 14:47:42 -0800 (PST) Received: from skynet.be (dialup227.herentals.skynet.be [195.238.28.227]) by excalibur.skynet.be (8.11.6/8.11.6/Skynet-OUT-2.16) with ESMTP id fBGMjT822774; Sun, 16 Dec 2001 23:45:29 +0100 (MET) (envelope-from ) Message-ID: <3C1D23FC.2010207@skynet.be> Date: Sun, 16 Dec 2001 23:45:16 +0100 From: Raf Schietekat Reply-To: Raf_Schietekat@ieee.org User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:0.9.4) Gecko/20011019 Netscape6/6.2 X-Accept-Language: en-us MIME-Version: 1.0 To: Matt Piechota Cc: FreeBSD-security@FreeBSD.ORG Subject: Re: kdm grants ordinary users root access on 4.4-R References: <20011215132828.P59641-100000@cithaeron.argolis.org> <3C1BCE3B.4010102@skynet.be> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Raf Schietekat wrote: > Matt Piechota wrote: > >> [...] >> Strange. My kde2 (or are we talking kde1?) doesn't show this behavior. That's probably because you configured it correctly. As I have written, I had used xdm's Xsession for kdm's Xstartup (there was no error message for Xsession at that point, and xdm didn't have an Xstartup, so I just guessed... wrong, and it only seemed to work). Now I've moved it back to Xsession and put some proper echo "#!/bin/sh" contents in Xreset and in a new Xstartup. After that, the problem disappeared. I have reported this on bugs.kde.org. Now I have to see about some proper documentation about this for FreeBSD (if it exists, I missed it). > > >[...] -- Raf Schietekat To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message