light-locker: desktop visible after resume from suspend

Bug #1529150 reported by Alad Wenter
266
This bug affects 3 people
Affects Status Importance Assigned to Milestone
light-locker (Ubuntu)
Expired
Low
Unassigned

Bug Description

After resuming from suspend in Xubuntu Wily, the desktop is briefly visible (~1s) before the unlock dialog from light-locker appears.

https://github.com/the-cavalry/light-locker/issues/63

This upstream commit appears to solve the issue:

https://github.com/the-cavalry/light-locker/commit/c026c663303ba1cfe0cde4bc011419645392ae62

A patch that applies to the Ubuntu package is attached.

ProblemType: Bug
DistroRelease: Ubuntu 15.10
Package: gnome-screensaver (not installed)
ProcVersionSignature: Ubuntu 4.2.0-16.19-generic 4.2.3
Uname: Linux 4.2.0-16-generic x86_64
ApportVersion: 2.19.1-0ubuntu5
Architecture: amd64
CurrentDesktop: XFCE
Date: Thu Dec 24 20:26:45 2015
InstallationDate: Installed on 2015-12-24 (0 days ago)
InstallationMedia: Xubuntu Core 15.10 - amd64 - 20151022
SourcePackage: gnome-screensaver
Symptom: security
Title: Screen locking issue
UpgradeStatus: No upgrade log present (probably fresh install)

Revision history for this message
Alad Wenter (the-changing-side) wrote :
affects: gnome-screensaver (Ubuntu) → light-locker (Ubuntu)
information type: Private Security → Public Security
Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

The attachment "Register systemd suspend delay" seems to be a patch. If it isn't, please remove the "patch" flag from the attachment, remove the "patch" tag, and if you are a member of the ~ubuntu-reviewers, unsubscribe the team.

[This is an automated message performed by a Launchpad user owned by ~brian-murray, for any issues please contact him.]

tags: added: patch
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in light-locker (Ubuntu):
status: New → Incomplete
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Alad, nice find, are you in a position that you can prepare and test updated packages? Thanks

Mathew Hodson (mhodson)
Changed in light-locker (Ubuntu):
importance: Undecided → Low
Revision history for this message
Tim Lunn (darkxst) wrote :

This patch is already included in the 1.7.0 release that is in Xenial. For a backport to wily it will need the patch applied to wily packaging and SRU process followed. Unsubscribing ubuntu-sponsors until that is complete.

tags: removed: patch
Revision history for this message
tbys (tbys) wrote :

I think this need to be set to importance: High, as it allows a malicious user to see any information displayed on the desktop without logging in.

Revision history for this message
Harry P (hjwp2) wrote :

I reported a similar bug here:

https://bugs.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/1509711

(looks like exactly the same thing)

seems it was fixed by the xenial upgrade?

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for light-locker (Ubuntu) because there has been no activity for 60 days.]

Changed in light-locker (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.