Lock screen can lose focus and send keystrokes to some other application

Bug #1399502 reported by Mike Gerow
260
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Unity
Incomplete
Undecided
Unassigned
unity (Ubuntu)
Incomplete
Undecided
Unassigned

Bug Description

I have a user that reported the unity lock screen losing focus and sending keystrokes to the application behind it. This seems similar to https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1358504 but that bug is marked as fixed.

In their specific case they were using chrome with google hangouts (using chrome's google hangouts extension: <https://chrome.google.com/webstore/detail/hangouts/nckgahadagoaajjgafhacjanaoiihapd?hl=en>) when they locked their screen. Upon coming back they typed their password and hit enter, but the screen did not unlock. They had to manually click in the password field and type their password before it would unlock. Upon unlocking they discovered that they had a hangouts window open with a colleague and had sent their password to them (I'm assuming during that first try when the lock screen did not unlock).

$ lsb_release -rd
Description: Ubuntu 14.04.1 LTS
Release: 14.04

$ apt-cache policy unity
unity:
  Installed: 7.2.3+14.04.20140826-0ubuntu1.0.1

I'm currently trying to find a way to reproduce this, but haven't managed to yet.

Mike Gerow (gerow)
information type: Private Security → Public Security
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Mike, the number of reports of this kind of behaviour have dropped dramatically since this update was released; my first thought is that perhaps the computer hasn't been rebooted since 7.2.3+14.04.20140826-0ubuntu1.0.1 was installed, and an older version was still running.

Do you know if the session had been restarted since the package was installed?

Thanks

Revision history for this message
Mike Gerow (gerow) wrote :

The machine was rebooted a little over a day ago. I'm pretty certain it had the update well before then.

Andrea Azzarone (azzar1)
tags: added: lockscreen
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in unity (Ubuntu):
status: New → Confirmed
Will Cooke (willcooke)
tags: added: rls-w-incoming
Revision history for this message
Andrea Azzarone (azzar1) wrote :

Can you still reproduce this problem?

Changed in unity:
status: New → Incomplete
Changed in unity (Ubuntu):
status: Confirmed → Incomplete
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.