18 Xfce Major Security Bug Hibernate + Suspend Don't Lock Screen

Bug #1648932 reported by timoto
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Linux Mint
New
Undecided
Unassigned

Bug Description

Whilst Hibernate and Suspend function, they do not lock the desktop screen even though in Xfce Power Manager > System > "Lock screen when system is going for sleep" is checked.

1. Linux Mint 18 Xfce

2. Make sure "Lock screen when system is going for sleep" is checked.

3. Reproduce unexpected behaviour by launching the Menu > Log Out > Suspend or Hibernate. When Resuming from Suspend or Hibernate results in access to the desktop without being prompted for credentials.

4. Expected login window.

5. Always

This is inconsistent behaviour, since closing laptop lid or hitting power button, will cause Suspend or Hibernate resuming with login window as expected.

timoto (timoto)
information type: Private Security → Public Security
Revision history for this message
timoto (timoto) wrote :

Further version information:

$ xfce4-panel --version
xfce4-panel 4.12.0 (Xfce 4.12)

$ xfce4-session --version
xfce4-session 4.12.1 (Xfce 4.12)

$ xfce4-power-manager --version
Xfce Power Manager 1.4.4

Revision history for this message
timoto (timoto) wrote :

Further settings information:

$ xfconf-query -c xfce4-power-manager -l -v
/xfce4-power-manager/brightness-on-ac 120
/xfce4-power-manager/brightness-switch 0
/xfce4-power-manager/brightness-switch-restore-on-exit 1
/xfce4-power-manager/critical-power-action 2
/xfce4-power-manager/hibernate-button-action 2
/xfce4-power-manager/inactivity-on-battery 14
/xfce4-power-manager/lid-action-on-ac 2
/xfce4-power-manager/lid-action-on-battery 2
/xfce4-power-manager/lock-screen-suspend-hibernate true
/xfce4-power-manager/logind-handle-lid-switch false
/xfce4-power-manager/power-button-action 2
/xfce4-power-manager/show-tray-icon 1
/xfce4-power-manager/sleep-button-action 2

$ xfconf-query -c xfce4-session -l -v
/general/AutoSave false
/general/FailsafeSessionName Failsafe
/general/SaveOnExit false
/general/SessionName Default
/sessions/Failsafe/Client0_Command <<UNSUPPORTED>>
/sessions/Failsafe/Client0_PerScreen false
/sessions/Failsafe/Client1_Command <<UNSUPPORTED>>
/sessions/Failsafe/Client1_PerScreen false
/sessions/Failsafe/Client2_Command <<UNSUPPORTED>>
/sessions/Failsafe/Client2_PerScreen false
/sessions/Failsafe/Client3_Command <<UNSUPPORTED>>
/sessions/Failsafe/Client3_PerScreen false
/sessions/Failsafe/Client4_Command <<UNSUPPORTED>>
/sessions/Failsafe/Client4_PerScreen false
/sessions/Failsafe/Count 5
/sessions/Failsafe/IsFailsafe true
/shutdown/LockScreen true

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.