Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 12 Feb 2010 14:33:29 +0100
From: Marcus Meissner <meissner@...e.de>
To: OSS Security List <oss-security@...ts.openwall.com>
Subject: CVE Request: KDE screensaver unlock issue similar to GNOME one

Hi,

Lots of our users also tested if the KDE screenlock program is affected
by the "unlock by pressing return" bug.

And it is.

There is also a race condition and/or a memory leak which causes
the lock program to terminate.

https://bugzilla.novell.com/show_bug.cgi?id=579280
http://bugs.kde.org/show_bug.cgi?id=217882
http://bugs.kde.org/show_bug.cgi?id=226449

Suspend to * is not required, it also works just by pressing return.
For me it takes like 5 seconds. Machine load might help.

It is unclear which KDE versions are affected, reports mostly show
KDE 4.4.0.

Needs a different CVE than the GNOME one.

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.