|
|
Message-ID: <4DADC8E1.9050707@redhat.com>
Date: Tue, 19 Apr 2011 19:39:45 +0200
From: Jan Lieskovsky <jlieskov@...hat.com>
To: "Steven M. Christey" <coley@...us.mitre.org>
CC: oss-security <oss-security@...ts.openwall.com>,
Richard Hughes <rhughes@...hat.com>, Ray Strode <rstrode@...hat.com>,
lsof@...ata.co.uk
Subject: CVE Request -- gnome-desktop3: Switching users dialog does not lock
the screen for the original user account
Hello Josh, Steve, vendors,
it has been reported that using of Gnome upon using of "Switch user" dialog, log in into a
new user account (user2), logout of new user account (user2) the desktop is returned to the
original user account (for user1) without prompting for a password. A locally proximate
attacker could use this flaw to access resources, which should be otherwise protected
by authentication.
Original report:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=697199
Upstream bug report:
[2] https://bugzilla.gnome.org/show_bug.cgi?id=648234
Could you allocate a CVE id for this?
Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.