HUD "Super" and "Alt" shortcuts works through locked screen

Bug #1266464 reported by Vladimir Rutsky
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Unity
Fix Released
High
Andrea Azzarone
hud (Ubuntu)
Invalid
Undecided
Unassigned
unity (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

To reproduce:
1. Lock screen (e.g. using Ctrl+Alt+L or corresponding option in menu).
2. Press Super (or Alt) key.
3. Enter password to unlock desktop.

Expected behaviour: nothing on desktop should be changed.
Observed behaviour: HUD menu pupped up, as if Alt or Super were pressed on desktop.

I mark this bug report as security issue, because not sure is Super and Alt keys are only shortcuts that being passed to desktop, if other keys can be passed to desktop in any way it would be possible to run some command through HUD.

ProblemType: Bug
DistroRelease: Ubuntu 13.10
Package: hud 13.10.1+13.10.20131031-0ubuntu1
ProcVersionSignature: Ubuntu 3.11.0-15.23-generic 3.11.10
Uname: Linux 3.11.0-15-generic x86_64
ApportVersion: 2.12.5-0ubuntu2.2
Architecture: amd64
CheckboxSubmission: 3d16077c4fdd6a017d47f6e3dc4f3c54
CheckboxSystem: b633b4f40868d491c2ae5b50030ce6f3
Date: Mon Jan 6 17:18:05 2014
InstallationDate: Installed on 2014-01-01 (4 days ago)
InstallationMedia: Ubuntu 13.10 "Saucy Salamander" - Release amd64 (20131016.1)
MarkForUpload: True
SourcePackage: hud
UpgradeStatus: No upgrade log present (probably fresh install)

Related branches

Revision history for this message
Vladimir Rutsky (rutsky) wrote :
Changed in hud (Ubuntu):
status: New → Confirmed
Revision history for this message
Seth Arnold (seth-arnold) wrote :

I've confirmed the behaviour; it does not appear to provide any ability to further cross privilege boundaries, so I'm marking it public / not-security. I'm also not sure if hud is the right target, I know Unity has some special handling around the Meta and Super keys.

Thanks

information type: Private Security → Public
Revision history for this message
Pete Woods (pete-woods) wrote :

The HUD project is just the back-end, it doesn't handle the user interface at all.

no longer affects: hud
Changed in hud (Ubuntu):
status: Confirmed → Invalid
Changed in unity:
status: New → Confirmed
Changed in unity:
milestone: none → 7.2.0
assignee: nobody → Andrea Azzarone (andyrock)
importance: Undecided → High
status: Confirmed → In Progress
Changed in unity:
status: In Progress → Fix Released
status: Fix Released → Fix Committed
Changed in unity (Ubuntu):
status: New → Fix Released
Revision history for this message
Stephen M. Webb (bregma) wrote :

Fix Released in Unity Unity 7.2.0.

Changed in unity:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.