Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 202649 (CVE-2007-6389) - gnome-extra/gnome-screensaver-2.20.0 Allows unauthorized disclosure of information (CVE-2007-6389)
Summary: gnome-extra/gnome-screensaver-2.20.0 Allows unauthorized disclosure of inform...
Status: RESOLVED FIXED
Alias: CVE-2007-6389
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://bugzilla.gnome.org/show_bug.cg...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-12-18 07:25 UTC by Lars Hartmann
Modified: 2008-03-04 14:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-12-18 07:25:02 UTC
CVE-2007-6389 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6389):
  The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might
  allow local users to read the clipboard contents and X selection data for a
  locked session by using ctrl-V.
Comment 1 Lars Hartmann 2007-12-18 07:32:09 UTC
The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2007-12-18 20:26:29 UTC
There are patches available here, but I have to agree with the last comments on the GNOME bug that clearing without restoring might not be expected behavior.
Comment 3 Lars Hartmann 2007-12-19 07:19:25 UTC
dito, applying this patches would be a fault imo.
This would cause many bugreports about problems with the clipboard
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-01-06 18:28:57 UTC
Setting to upstream status until we have a proper patch.
Comment 5 Mart Raudsepp gentoo-dev 2008-02-19 12:41:21 UTC
CCing maintainers...
Do we need to do anything? It seems upstream went with data loss and is seeing if someone cares about the clipboard data loss
Comment 6 Robert Buchholz (RETIRED) gentoo-dev 2008-02-19 16:30:41 UTC
Mart, thanks for getting back on this bug.

This thing is stable, so we're here for GLSA decision. I tend to vote yes.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2008-02-20 08:28:58 UTC
I tend to vote NO.
Comment 8 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-03-04 14:25:23 UTC
I vote NO.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-03-04 14:26:34 UTC
reverting to NO then, closing.