Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 19 Apr 2011 19:39:45 +0200
From: Jan Lieskovsky <jlieskov@...hat.com>
To: "Steven M. Christey" <coley@...us.mitre.org>
CC: oss-security <oss-security@...ts.openwall.com>,
        Richard Hughes <rhughes@...hat.com>, Ray Strode <rstrode@...hat.com>,
        lsof@...ata.co.uk
Subject: CVE Request -- gnome-desktop3: Switching users dialog does not lock
 the screen for the original user account


Hello Josh, Steve, vendors,

   it has been reported that using of Gnome upon using of "Switch user" dialog, log in into a
new user account (user2), logout of new user account (user2) the desktop is returned to the
original user account (for user1) without prompting for a password. A locally proximate
attacker could use this flaw to access resources, which should be otherwise protected
by authentication.

Original report:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=697199

Upstream bug report:
[2] https://bugzilla.gnome.org/show_bug.cgi?id=648234

Could you allocate a CVE id for this?

Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.