Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 566090 (CVE-2015-7496) - <gnome-base/gdm-3.18.2: crash when holding Escape in lock screen (CVE-2015-7496)
Summary: <gnome-base/gdm-3.18.2: crash when holding Escape in lock screen (CVE-2015-7496)
Status: RESOLVED FIXED
Alias: CVE-2015-7496
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~3 [noglsa/cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-11-17 22:13 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2015-11-19 19:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-11-17 22:13:36 UTC
From ${URL}:

Credit to my cat for finding this..

* Running gnome session
* Press <super>+l to lock
* Press Escape and hold

Expected:

* The slider thing going up an down in an endless loop

Happing:

* After ~5 times the slider window coming and going GS crashes
##

From https://bugzilla.gnome.org/show_bug.cgi?id=758032

3.18.2 tarball is released now. 3.19.2 unstable tarball can't easily go out until monday since it relies on releases in gnome-session / mutter and gnome-shell for other reasons.
Comment 1 Gilles Dartiguelongue (RETIRED) gentoo-dev 2015-11-17 23:01:47 UTC
Just tested this on gdm-3.16.4 and it works just fine, no crashes.
Comment 2 Ole Reifschneider (RETIRED) gentoo-dev 2015-11-18 21:52:07 UTC
I can't reproduce it with 3.18.0.

3.18.2 however contains 2 commits that reference the related bug on the gnome bugtracker.
Comment 3 Pacho Ramos gentoo-dev 2015-11-19 19:07:55 UTC
3.18.2 bumped and 3.18.0 removed
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-11-19 19:29:20 UTC
(In reply to Pacho Ramos from comment #3)
> 3.18.2 bumped and 3.18.0 removed

Thanks, 

based in this discussion it seems current stable 3.16 is not affected and as such reducing priority. As bump and cleanup for the masked 3.18 is done, closing as fixed.