kdesktop_locker crashes if Scim Anthy input is selected

Bug #270669 reported by TWO
6
Affects Status Importance Assigned to Milestone
kdebase (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

#Kubuntu Hardy Heron 7.10
#KDE 3.5.9
#System locale: English (en_GB)

Packages:
kdesktop 4:3.5.9-0ubuntu7.3
scim 1.4.7-3ubuntu8
scim-anthy 1.2.4-1ubuntu2
scim-bridge 0.4.12-1ubuntu1
scim-bridge-agent 0.4.14-1ubuntu2
scim-bridge-client-gtk 0.4.14-1ubuntu2
scim-bridge-client-qt 0.4.14-1ubuntu2
scim-bridge-client-qt4 0.4.14-1ubuntu2
scim-gtk2-immodule 1.4.7-3ubuntu8
scim-modules-socket 1.4.7-3ubuntu8
skim-scim-anthy 1.2.4-0ubuntu2
skim 1.4.5-4ubuntu3
libskim0 1.4.5-4ubuntu3

Problem:

The screen lock facility will crash if 'cancel' is chosen during the password prompt, so long as one has Anthy selelected as the input method for Scim. When the program crashes, the user is returned to the desktop screen and has in turn succeeded in bypassing the screen lock without knowledge of the password. This could be a potential security issue for systems running Scim.

Steps to reproduce:

Set Scim's input method to 'Anthy,' then either wait for the password protected screensaver to start or lock the screen manually. Now click on the 'cancel' button when the password prompt appears and this should reproduce the crash.

Now, set Scim's input method to 'English/European' and then lock the screen. You should find that clicking cancel removes the password prompt and doesn't crash kdesktop_lock.

Revision history for this message
TWO (two) wrote :
Revision history for this message
TWO (two) wrote :

No else managed to reproduce this one? I'd imagine that it was a pretty crucial one.

Revision history for this message
TWO (two) wrote :

This problem also occurs when Anthy is set to Latin mode.

Revision history for this message
Harald Sitter (apachelogger) wrote :

Should be fixed in Kubuntu Intrepid.

Changed in kdebase:
status: New → Fix Released
Revision history for this message
TWO (two) wrote :

Is it at all possible for this fix to be put in the hardy-backports?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.