Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 202649 (CVE-2007-6389)

Summary: gnome-extra/gnome-screensaver-2.20.0 Allows unauthorized disclosure of information (CVE-2007-6389)
Product: Gentoo Security Reporter: Lars Hartmann <lars>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: gnome
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://bugzilla.gnome.org/show_bug.cgi?id=482159
Whiteboard: B4 [noglsa]
Package list:
Runtime testing required: ---

Description Lars Hartmann 2007-12-18 07:25:02 UTC
CVE-2007-6389 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6389):
  The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might
  allow local users to read the clipboard contents and X selection data for a
  locked session by using ctrl-V.
Comment 1 Lars Hartmann 2007-12-18 07:32:09 UTC
The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-12-18 20:26:29 UTC
There are patches available here, but I have to agree with the last comments on the GNOME bug that clearing without restoring might not be expected behavior.
Comment 3 Lars Hartmann 2007-12-19 07:19:25 UTC
dito, applying this patches would be a fault imo.
This would cause many bugreports about problems with the clipboard
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-01-06 18:28:57 UTC
Setting to upstream status until we have a proper patch.
Comment 5 Mart Raudsepp gentoo-dev 2008-02-19 12:41:21 UTC
CCing maintainers...
Do we need to do anything? It seems upstream went with data loss and is seeing if someone cares about the clipboard data loss
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-02-19 16:30:41 UTC
Mart, thanks for getting back on this bug.

This thing is stable, so we're here for GLSA decision. I tend to vote yes.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-20 08:28:58 UTC
I tend to vote NO.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-03-04 14:25:23 UTC
I vote NO.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-03-04 14:26:34 UTC
reverting to NO then, closing.