Bug 4209 - Xserver locking bypass from keyboard without any password.
Summary: Xserver locking bypass from keyboard without any password.
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Thierry Vignaud
QA Contact:
URL: http://www.h-online.com/security/news...
Whiteboard:
Keywords: Triaged
Depends on:
Blocks:
 
Reported: 2012-01-20 18:45 CET by Jari S
Modified: 2012-02-01 11:48 CET (History)
2 users (show)

See Also:
Source RPM: x11-server
CVE:
Status comment:


Attachments

Description Jari S 2012-01-20 18:45:20 CET
Description of problem:
Xserver locking bypass.
http://www.h-online.com/security/news/item/X-org-server-allows-anyone-to-unlock-computer-1417864.html

Version-Release number of selected component (if applicable):
x11-server-xorg-1.11.3.901-1.mga2

How reproducible:
Always. Tested with both KDE and GNOME.

Steps to Reproduce:
1. Startx
2. If laptop then put NumLock on
3. Press CTRL+ATL+* (Lenovo laptop key P which is numpad *).
Comment 1 Dave Hodgins 2012-01-20 23:12:20 CET
Bug confirmed on cauldron with a desktop i586 system.

CC: (none) => davidwhodgins
Hardware: x86_64 => All

Comment 2 Manuel Hiebel 2012-01-23 00:44:03 CET
Hi, thanks for reporting this bug.
Assigned to the package maintainer.

(Please set the status to 'assigned' if you are working on it)

Keywords: (none) => Triaged
Assignee: bugsquad => thierry.vignaud
Source RPM: x11-server-xorg-1.11.3.901-1.mga2 => x11-server

Florian Hubold 2012-01-24 11:35:51 CET

CC: (none) => doktor5000

Comment 3 Manuel Hiebel 2012-02-01 11:48:32 CET
As we have a new version, I guess it can be closed

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.