Activity log for bug #474654

Date Who What changed Old value New value Message
2009-11-04 20:02:58 goto bug added bug
2009-11-04 20:02:58 goto attachment added oh noes, i'm lookin' at ur desktop! http://launchpadlibrarian.net/35113384/broken-lock-1.jpg
2009-11-04 20:03:44 goto visibility private public
2009-11-04 20:08:29 goto attachment added i'm spyin' on ur googls! http://launchpadlibrarian.net/35113770/broken-lock-2.jpg
2009-11-04 20:11:16 goto description Sometimes when the screen is locked and I press a key to unlock it, I see my entire desktop and open windows under the password dialog box. That's a security problem. I believe this is a compositing / video memory issue, because of the following factors: 1.) It is intermittent, but occurs most when the screen is "busy" (lots of graphics-heavy windows open). 2.) I can almost always reproduce it by doing something video-intensive, such as x11perf. 3.) Sometimes everything will be visible except that one or two windows, or the "active" portions thereof, will be blacked out. 4.) I have seen other compositing / video memory glitches, such as the contents of a previously closed window appearing briefly in a newly opened window before it completes drawing (another security issue in its own right). 5.) The desktop is shown as it appeared when the screen was locked, and does not update while locked. 6.) I am unable to reproduce the issue with compositing ("desktop effects") disabled. Note that the desktop is not dimmed; it is visible for as long as you want to stare at it, even after the password prompt has disappeared; and I am using dualhead and both screens are visible, so this is not a duplicate of #390989 or #385102 or #417722, though it is probably related. I have attached a screenshot (acquired via VNC) demonstrating the problem. I'm running Kubuntu 9.04 x86-64 with all updates, using the NVidia 180.44 binary driver with TwinView on a GeForce 8400 GS. Sometimes when the screen is locked and I press a key to unlock it, I see my entire desktop and open windows under the password dialog box. That's a security problem. I believe this is a compositing / video memory issue, because of the following factors: 1.) It is intermittent, but occurs most when the screen is "busy" (lots of graphics-heavy windows open). 2.) I can almost always reproduce it by doing something video-intensive, such as x11perf. 3.) Sometimes everything will be visible except that one or two windows, or the "active" portions thereof, will be blacked out. 4.) I have seen other compositing / video memory glitches, such as the contents of a previously closed window appearing briefly in a newly opened window before it completes drawing (another security issue in its own right). 5.) The desktop is shown as it appeared when the screen was locked, and does not update while locked. 6.) I am unable to reproduce the issue with compositing ("desktop effects") disabled. Note that the desktop is not dimmed; it is visible for as long as you want to stare at it, even after the password prompt has disappeared; and I am using dualhead and both screens are visible, so this is not a duplicate of #390989 or #385102 or #417722, though it is probably related. I have attached two screenshots (acquired via VNC) demonstrating the problem. I'm running Kubuntu 9.04 x86-64 with all updates, using the NVidia 180.44 binary driver with TwinView on a GeForce 8400 GS.
2009-11-06 13:38:10 Marc Deslauriers ubuntu: status New Confirmed
2010-01-31 18:11:08 KIAaze attachment added lspci -vvnn http://launchpadlibrarian.net/38584623/lspci.log
2010-08-29 13:39:42 Mohamed Amine Ilidrissi affects ubuntu kdebase-workspace (Ubuntu)
2010-08-29 13:39:42 Mohamed Amine Ilidrissi kdebase-workspace (Ubuntu): status Confirmed Incomplete
2010-08-29 14:39:31 Philip Muškovac kdebase-workspace (Ubuntu): status Incomplete Confirmed
2010-08-29 14:59:06 Mohamed Amine Ilidrissi bug watch added http://bugs.kde.org/show_bug.cgi?id=249417
2010-08-29 14:59:06 Mohamed Amine Ilidrissi bug task added kdebase
2010-08-31 23:36:30 Bug Watch Updater kdebase: status Unknown New
2010-09-07 10:52:41 Andrey Bondarenko bug added subscriber Andrey Bondarenko
2010-10-26 04:24:46 Bug Watch Updater kdebase: status New Unknown
2010-10-26 14:30:50 Andrey Bondarenko removed subscriber Andrey Bondarenko
2011-02-03 20:17:17 Bug Watch Updater kdebase: importance Unknown Medium
2011-02-25 13:58:22 Bug Watch Updater kdebase: status Unknown Invalid
2011-04-16 13:45:53 Maarten Bezemer bug watch added http://bugs.kde.org/show_bug.cgi?id=246623
2011-04-16 13:45:53 Maarten Bezemer kdebase: importance Medium Unknown
2011-04-16 13:45:53 Maarten Bezemer kdebase: status Invalid Unknown
2011-04-16 13:45:53 Maarten Bezemer kdebase: remote watch KDE Bug Tracking System #249417 KDE Bug Tracking System #246623
2011-04-16 14:35:15 Bug Watch Updater kdebase: status Unknown New
2011-04-16 14:35:15 Bug Watch Updater kdebase: importance Unknown Medium
2011-04-27 16:13:42 Jamie Strandboge summary Desktop visible when screen is locked in Kubuntu [SecurityRoadmap] Desktop visible when screen is locked in Kubuntu
2011-10-02 23:01:23 Harald Sitter kdebase-workspace (Ubuntu): status Confirmed Invalid
2011-10-19 19:49:23 Jamie Strandboge removed subscriber Ubuntu Security Team
2012-06-30 20:56:55 Bug Watch Updater bug watch added https://bugzilla.redhat.com/show_bug.cgi?id=677345
2013-01-06 22:19:04 Bug Watch Updater bug watch added https://bugs.kde.org/show_bug.cgi?id=183496
2013-04-16 13:53:35 Bug Watch Updater kde-baseapps: status New Fix Released