Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 496168 (CVE-2013-7221) - <gnome-base/gnome-shell-3.8.4-r2: run command dialog visible above screen locker (CVE-2013-7221)
Summary: <gnome-base/gnome-shell-3.8.4-r2: run command dialog visible above screen loc...
Status: RESOLVED FIXED
Alias: CVE-2013-7221
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-27 14:13 UTC by Agostino Sarubbo
Modified: 2014-01-06 22:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-12-27 14:13:16 UTC
From ${URL} :

In Fedora 19, the "Enter the Command" dialog box is visible even after
you lock the screen, so anyone can write the commands in the box and
execute them over a locked screen.

Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=708313

Upstream patch:
https://git.gnome.org/browse/gnome-shell/commit/js/ui/main.js?id=efdf1ff755943fba1f8a9aaeff77daa3ed338088

This issue has been addressed in gnome-shell-3.10.0

Reference: https://bugzilla.redhat.com/show_bug.cgi?id=1046839


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Pacho Ramos gentoo-dev 2013-12-27 21:11:43 UTC
Better to stabilize this version instead:
+*gnome-shell-3.8.4-r2 (27 Dec 2013)
+
+  27 Dec 2013; Pacho Ramos <pacho@gentoo.org>
+  +files/gnome-shell-3.8.4-close-rundialog.patch, +gnome-shell-3.8.4-r2.ebuild:
+  Fix security bug #496168
+
Comment 2 Agostino Sarubbo gentoo-dev 2013-12-27 21:30:09 UTC
Arches please test and stabilize:

=gnome-base/gnome-shell-3.8.4-r2

target keywords="amd64 x86"
Comment 3 Pacho Ramos gentoo-dev 2013-12-27 23:29:17 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2014-01-05 09:06:29 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 5 Pacho Ramos gentoo-dev 2014-01-05 10:19:54 UTC
cleaned
Comment 6 Chris Reffett (RETIRED) gentoo-dev Security 2014-01-05 14:57:40 UTC
GLSA vote: no.
Comment 7 Sergey Popov gentoo-dev 2014-01-06 22:41:20 UTC
Thanks for your work.

GLSA vote: no

Closing as noglsa