[SecurityRoadmap] screensaver unlock dialog under other windows

Bug #487165 reported by Chris Jones
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
compiz (Ubuntu)
Expired
Medium
Unassigned

Bug Description

Binary package hint: compiz

I suspended my laptop as usual at some point yesterday. This morning I opened the lid and was presented with my desktop, then I noticed that the screensaver unlock screen was *under* my terminals, but obviously it had full focus, so I was able to type my password and continue working.

I've never seen this before, but I hope its severity is obvious.

Revision history for this message
Chris Jones (cmsj) wrote :
Revision history for this message
Chris Jones (cmsj) wrote : apport-collect data

Architecture: amd64
CompizPlugins: [core,move,resize,place,decoration,animation,ccp,dbus,mousepoll,gnomecompat,png,svg,imgjpeg,text,neg,video,wall,snap,scale,scaleaddon,expo,staticswitcher,regex,resizeinfo,workarounds,ezoom,vpswitch,extrawm,fade,session]
DistroRelease: Ubuntu 9.10
InstallationMedia: Ubuntu 9.10 "Karmic Koala" - Release Candidate amd64 (20091020.3)
MachineType: LENOVO 2777CTO
Package: compiz 1:0.8.4-0ubuntu2
PackageArchitecture: all
PciDisplay: 00:02.0 VGA compatible controller [0300]: Intel Corporation Mobile 4 Series Chipset Integrated Graphics Controller [8086:2a42] (rev 07)
ProcCmdLine: BOOT_IMAGE=/boot/vmlinuz-2.6.31-14-generic root=UUID=19b37e21-1c52-464f-94b6-d44278daa146 ro quiet splash
ProcEnviron:
 SHELL=/bin/bash
 PATH=(custom, user)
 LANG=en_GB.UTF-8
ProcVersionSignature: Ubuntu 2.6.31-14.48-generic
RelatedPackageVersions:
 xserver-xorg 1:7.4+3ubuntu7
 libgl1-mesa-glx 7.6.0-1ubuntu4
 libdrm2 2.4.14-1ubuntu1
 xserver-xorg-video-intel 2:2.9.0-1ubuntu2
 xserver-xorg-video-ati 1:6.12.99+git20090929.7968e1fb-0ubuntu1
Uname: Linux 2.6.31-14-generic x86_64
UserGroups: adm admin cdrom dialout libvirtd lpadmin plugdev sambashare
XorgConf: Error: [Errno 2] No such file or directory: '/etc/X11/xorg.conf'
dmi.bios.date: 05/15/2009
dmi.bios.vendor: LENOVO
dmi.bios.version: 6EET41WW (3.01 )
dmi.board.name: 2777CTO
dmi.board.vendor: LENOVO
dmi.board.version: Not Available
dmi.chassis.asset.tag: No Asset Information
dmi.chassis.type: 10
dmi.chassis.vendor: LENOVO
dmi.chassis.version: Not Available
dmi.modalias: dmi:bvnLENOVO:bvr6EET41WW(3.01):bd05/15/2009:svnLENOVO:pn2777CTO:pvrThinkPadX301:rvnLENOVO:rn2777CTO:rvrNotAvailable:cvnLENOVO:ct10:cvrNotAvailable:
dmi.product.name: 2777CTO
dmi.product.version: ThinkPad X301
dmi.sys.vendor: LENOVO
system: distro = Ubuntu, architecture = x86_64, kernel = 2.6.31-14-generic

Revision history for this message
Chris Jones (cmsj) wrote : BootDmesg.gz
Revision history for this message
Chris Jones (cmsj) wrote : CurrentDmesg.txt
Revision history for this message
Chris Jones (cmsj) wrote : Dependencies.txt
Revision history for this message
Chris Jones (cmsj) wrote : GconfCompiz.txt
Revision history for this message
Chris Jones (cmsj) wrote : Lspci.txt
Revision history for this message
Chris Jones (cmsj) wrote : Lsusb.txt
Revision history for this message
Chris Jones (cmsj) wrote : ProcCpuinfo.txt
Revision history for this message
Chris Jones (cmsj) wrote : ProcInterrupts.txt
Revision history for this message
Chris Jones (cmsj) wrote : ProcModules.txt
Revision history for this message
Chris Jones (cmsj) wrote : UdevDb.txt
Revision history for this message
Chris Jones (cmsj) wrote : UdevLog.txt
Revision history for this message
Chris Jones (cmsj) wrote : XorgLog.txt
Revision history for this message
Chris Jones (cmsj) wrote : XorgLogOld.txt
Revision history for this message
Chris Jones (cmsj) wrote : Xrandr.txt
Revision history for this message
Chris Jones (cmsj) wrote : XsessionErrors.txt
Revision history for this message
Chris Jones (cmsj) wrote : glxinfo.txt
Revision history for this message
Chris Jones (cmsj) wrote : monitors.xml.txt
tags: added: apport-collected
Revision history for this message
WeatherGod (ben-v-root) wrote : Re: screensaver unlock dialog under other windows

Chris, thank you for reporting this issue. I agree, this is a serious issue. Is this a repeatable problem? Maybe it only occurs if you close your lid when plugged/unplugged or maybe the plug status changes while closed? Are the other screen items accessible, or does the password dialogue maintains the focus?

Changed in compiz (Ubuntu):
status: New → Incomplete
Revision history for this message
Chris Jones (cmsj) wrote :

I've never seen it before or since and I'm locking/suspending/plugging/unplugging my laptop many times each day.
The password dialog had focus, so I wasn't able to interact with the other windows in any way, but they were visible which is obviously undesirable.

Changed in compiz (Ubuntu):
status: Incomplete → New
Revision history for this message
WeatherGod (ben-v-root) wrote :

Chris, which desktop manager are you using? Also, are you using standard Ubuntu, Kubuntu, Xubuntu...?

WeatherGod (ben-v-root)
security vulnerability: no → yes
Changed in compiz (Ubuntu):
status: New → Incomplete
Revision history for this message
Chris Jones (cmsj) wrote :

Fairly stock Ubuntu with Compiz and GNOME. I have a second monitor attached to my laptop when I'm at work, so that was almost certainly attached at the time.

Changed in compiz (Ubuntu):
status: Incomplete → New
Kees Cook (kees)
Changed in compiz (Ubuntu):
status: New → Confirmed
Revision history for this message
Chris Jones (cmsj) wrote :

This happened again this morning, this time I happened to notice that Docky was bouncing an attention grabbing icon because I'd plugged in my phone (I use Docky's Mounter plugin) and someone was trying to talk to me through Empathy/jabber. Might be related?

Changed in compiz (Ubuntu):
importance: Undecided → Medium
tags: added: dapper hardy karmic lucid maverick natty
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Does this still affect Ubuntu 11.04?

Changed in compiz (Ubuntu):
assignee: nobody → Jamie Strandboge (jdstrand)
status: Confirmed → Incomplete
summary: - screensaver unlock dialog under other windows
+ [SecurityRoadmap] screensaver unlock dialog under other windows
Changed in compiz (Ubuntu):
assignee: Jamie Strandboge (jdstrand) → nobody
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for compiz (Ubuntu) because there has been no activity for 60 days.]

Changed in compiz (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.