Comment 0 for bug 1627433

Revision history for this message
Nitish (nsp92) wrote :

This issue seems to be a moderately serious security hole which can be used to get access to someone's machine.

The following are steps to reproduce it:
1. Click and drag the title bar of any window which is open, such that it goes into "move" mode
2. Put the machine to sleep using the shortcut keys (present on most laptops) while still clicking on the mouse.
3. Release the mouse key after the machine goes to sleep
4. Wake the machine up again
5. When the machine wakes up, the lock screen is circumvented and you directly end up with an unlocked PC, i.e., no lockscreen or greeter comes into the picture.

Expected outcome:
When the PC wakes up from sleep, the user must be prompted with a lockscreen/greeter.

Note: Lockscreen was enabled on the machine in which this issue was found.

OS info -
---------
Description: Ubuntu 16.04.1 LTS
Release: 16.04

App info -
----------
lightdm-gtk-greeter:
  Installed: (none)
  Candidate: 2.0.1-2ubuntu4
  Version table:
     2.0.1-2ubuntu4 500
        500 http://archive.ubuntu.com/ubuntu xenial/universe amd64 Packages