Lockscreen indicators allow starting programs in the locked session

Bug #1291376 reported by Donarsson
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
unity (Ubuntu)
Invalid
Low
Unassigned

Bug Description

The indicators[1] in the new lockscreen allow starting associated programs like they would when the computer is unlocked.

Steps to reproduce:
* Lock the screen
* Click on "Character Map" in the keyboard-layout indicator menu
* Unlock the screen

The character map is now open in the previously locked session. This should not be possible, indicators should not allow such actions when the screen is locked.

This might even be a security vulnerability, as it is possible to crash the machine by starting multiple instances of the same program until it runs out of memory. I'm not sure if I should mark it as such, so I don't for now.

[1] keyboard-layout and power; probably datetime too, but I couldn't test this as I don't have evolution installed

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: unity 7.1.2+14.04.20140311-0ubuntu1
ProcVersionSignature: Ubuntu 3.13.0-17.37-generic 3.13.6
Uname: Linux 3.13.0-17-generic x86_64
ApportVersion: 2.13.3-0ubuntu1
Architecture: amd64
CompizPlugins: No value set for `/apps/compiz-1/general/screen0/options/active_plugins'
CurrentDesktop: Unity
Date: Wed Mar 12 14:14:31 2014
InstallationDate: Installed on 2014-02-24 (16 days ago)
InstallationMedia: Ubuntu 14.04 LTS "Trusty Tahr" - Alpha amd64 (20140223)
SourcePackage: unity
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Donarsson (benjamin-schwarz) wrote :
tags: added: lockscreen
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug report, that's not an unity issue but one with those indicators and it's known/reported/being worked already, see e.g bug #1256872

Changed in unity (Ubuntu):
status: New → Invalid
importance: Undecided → Low
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.