Major security issue with light-locker - console switching gives access to other screens for a few seconds
Bug #1515662 reported by
Nathan Neulinger
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
light-locker (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
lightdm (Ubuntu) |
Invalid
|
Undecided
|
Unassigned |
Bug Description
light-locker is completely insecure for X configurations with multiple screens that are not using a single display.
My setup - 4 monitors, nvidia, each with separate screen.
If I lock screen and then control-alt-f7 back to X, only one single screen is protected. After several seconds, it forces a switch to the lock display, but in the mean time, the other three screens are COMPLETELY UNPROTECTED.
It only takes a few seconds to launch a terminal and killall light-locker and I have unrestricted access to all.
Changed in light-locker (Ubuntu): | |
status: | New → Triaged |
To post a comment you must log in.
HI Nathan - Thanks for the bug report. I'm going to make it public so that more people can be aware of this issue in hopes that it'll get attention.