Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #178198
| From | Joe <joe@jretrading.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Security hole in LXDE? |
| Date | 2017-02-27 12:50 +0100 |
| Message-ID | <tfrYu-4Xq-3@gated-at.bofh.it> (permalink) |
| References | <tfpMZ-3yz-1@gated-at.bofh.it> <tfrlM-4I3-11@gated-at.bofh.it> <tfrF7-4Ql-25@gated-at.bofh.it> |
| Organization | JRE Trading Ltd |
On Mon, 27 Feb 2017 12:20:50 +0100 Hans <hans.ullrich@loop.de> wrote: > > Check how synaptic is being started by the menu entry. Typically, > > synaptic will be started by /usr/bin/synaptic-pkexec, which uses > > policykit to authorise an effective su for a normal user. The > > executable synaptic is in /usr/sbin, so will probably not work from > > a menu. > > Yes, it is as you said. There is /usr/bin/synaptic-pkexec > and /usr/sbin/synatic > > > > > I've changed the launcher to gksudo synaptic, which gives me > > explicit fine control with sudoers. > > > > As I said: I do NOT use sudoers, and there is no entry or the > user /etc/ sudoers. > > > I suspect what you're seeing is as intended. > > If so, then why not working so in KDE? And if this is intended, then > this is a bug and a security hole, which should be fixed. > I use neither LXDE nor KDE, so I would be guessing, but generally menu operation is a function of the desktop environment, and the KDE menu call may not be using pkexec. Or it may be using pkexec, but with a different policy in action. I have the common problem of using an old installation, with no recollection of the changes I have made over years to the default settings. For as long as I can remember, I have intended to log every change I make, and one day perhaps I will begin... -- Joe
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
[SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100
csiph-web