Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 524510 (CVE-2014-7300) - gnome-base/gnome-shell: lockscreen bypass with printscreen key
Summary: gnome-base/gnome-shell: lockscreen bypass with printscreen key
Status: RESOLVED FIXED
Alias: CVE-2014-7300
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-10-05 10:26 UTC by Agostino Sarubbo
Modified: 2016-06-27 11:42 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-10-05 10:26:39 UTC
From ${URL} :

gnome-shell currently handles the lockscreen for modern versions of gnome.

gnome-shell also handles the "take a screenshot" action, which is mapped
by default to the prtsc key.

the prtsc key is not disabled when the screen is locked.

taking a bunch of screenshots at once bloats gnome-shell to the point
where it's pretty easy to get it targeted by the kernel's oom-killer.

This means that anyone with access to the keyboard of a locked GNOME
session can (briefly) disable the lockscreen, which lets them see and
interact with the running gnome session:

  https://bugzilla.gnome.org/show_bug.cgi?id=737456

It looks like fixes are targeted for GNOME 3.14.1.



@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Pacho Ramos gentoo-dev 2015-10-17 11:12:36 UTC
this should be solved now with 3.16 in stable
Comment 2 Leho Kraav (:macmaN @lkraav) 2016-06-26 22:58:32 UTC
Is this waiting for something before closing?
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2016-06-27 05:05:00 UTC
No it just got missed.
GLSA Vote: No
Thank you all for you work. 
Closing as [noglsa].