Lockscreen does not appear when waking up from sleep mode

Bug #1627433 reported by Nitish
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
unity (Ubuntu)
Triaged
Undecided
Unassigned

Bug Description

This issue seems to be a moderately serious security hole which can be used to get access to someone's machine.

The following are steps to reproduce it:
1. Click and drag the title bar of any window which is open, such that it goes into "move" mode
2. Put the machine to sleep using the shortcut keys (present on most laptops) while still clicking on the mouse.
3. Release the mouse key after the machine goes to sleep
4. Wake the machine up again
5. When the machine wakes up, the lock screen is circumvented and you directly end up with an unlocked PC, i.e., no lockscreen or greeter comes into the picture.

Expected outcome:
When the PC wakes up from sleep, the user must be prompted with a lockscreen/greeter.

Note: Lockscreen was enabled on the machine in which this issue was found.

OS info:
--------
Description: Ubuntu 16.04.1 LTS
Release: 16.04

App info:
---------
unity-greeter:
  Installed: 16.04.2-0ubuntu1
  Candidate: 16.04.2-0ubuntu1
  Version table:
 *** 16.04.2-0ubuntu1 500
        500 http://archive.ubuntu.com/ubuntu xenial/main amd64 Packages
        100 /var/lib/dpkg/status

Display manager:
----------------
Lightdm

Lightdm configuration:
[SeatDefaults]
autologin-guest=false
autologin-user=
autologin-user-timeout=0
greeter-session=unity-greeter
autologin-session=lightdm-autologin
[SeatDefaults]
display-setup-script=/etc/lightdm/display-setup-script.sh

Nitish (nsp92)
description: updated
affects: lightdm-gtk-greeter (Ubuntu) → unity-greeter (Ubuntu)
description: updated
Emily Ratliff (emilyr)
affects: unity-greeter (Ubuntu) → unity (Ubuntu)
information type: Private Security → Public Security
Changed in unity (Ubuntu):
status: New → Triaged
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.