Passwords entered in GDM can be displayed when switching TTYs

Bug #1792924 reported by Alan Diggs
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gdm3 (Ubuntu)
New
Undecided
Unassigned

Bug Description

Ubuntu 18.04.1 LTS

gdm3:
  Installed: 3.28.2-0ubuntu1.4
  Candidate: 3.28.2-0ubuntu1.4
  Version table:
 *** 3.28.2-0ubuntu1.4 500
        500 http://us.archive.ubuntu.com/ubuntu bionic-updates/main amd64 Packages
        500 http://security.ubuntu.com/ubuntu bionic-security/main amd64 Packages
        100 /var/lib/dpkg/status
     3.28.0-0ubuntu1 500
        500 http://us.archive.ubuntu.com/ubuntu bionic/main amd64 Packages

When switching between TTYs or sessions via the Alt+Function keybindings, you can briefly display all entered passwords from the GDM password box. When I was switching from a TTY to my active GNOME Shell session, I accidentally pressed `Alt`+`F1`+`F2` at the same time instead of just `Alt`+`F2`, and when I did this, a black screen with text appeared for a second or so that displayed everything that had been entered into the GDM password box, regardless of which user it was. I believe this may be problematic on multi-user systems. I tried to take a picture but the quality is subpar as I had to handle the camera and press the keys at the same time to capture ( https://photos.app.goo.gl/8k5voYWcvK424xp59 ) The intentionally blurred area is where the passwords/entered text was shown.

ProblemType: Bug
DistroRelease: Ubuntu 18.04
Package: gdm3 3.28.2-0ubuntu1.4
Uname: Linux 4.18.7-041807-generic x86_64
ApportVersion: 2.20.9-0ubuntu7.3
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
Date: Mon Sep 17 05:12:33 2018
InstallationDate: Installed on 2018-09-15 (2 days ago)
InstallationMedia: Ubuntu 18.04.1 LTS "Bionic Beaver" - Release amd64 (20180725)
ProcEnviron:
 TERM=xterm-256color
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: gdm3
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Alan Diggs (schyken-deactivatedaccount) wrote :
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1767918, so it is being marked as such. Please look at the other bug report to see if there is any missing information that you can provide, or to see if there is a workaround for the bug. Additionally, any further discussion regarding the bug should occur in the other report. Feel free to continue to report any other bugs you may find.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.