Bug 1013789

Summary: ibus-mozc must be locked down while screen is locked
Product: [Fedora] Fedora Reporter: Yohei Yukawa <yukawa>
Component: mozcAssignee: Akira TAGOH <tagoh>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: i18n-bugs, tagoh
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: mozc-1.11.1522.102-3.fc20 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-10-19 09:06:23 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Yohei Yukawa 2013-09-30 19:12:08 UTC
Description of problem:
Anyone can use ibus-mozc on the Gnome Shell's locked screen, meaning that an arbitrary person is able to do the following things while you are away from your desk.
- See your private information as conversion candidates that come from your user dictionary entry and/or input history.
- Update your input history.
- Change config settings via "Command" feature.

Version-Release number of selected component (if applicable):
ibus-mozc.x86_64                       1.11.1522.102-2.fc21
ibus.x86_64                            1.5.4-1.fc21
ibus-gtk2.x86_64                       1.5.4-1.fc21
ibus-gtk3.x86_64                       1.5.4-1.fc21
gnome-shell.x86_64                     3.10.0.1-1.fc21

How reproducible:
100%

Steps to Reproduce:
1. Log in to Gnome
2. Add ibus-mozc into the active keyboard list
3. Lock screen from the Gnome Shell menu
4. Hit Hankaku/Zenkaku key to turn on ibus-mozc on the password field.

Actual results:
Anyone can use ibus-mozc that is running under the user's context after step 4.

Expected results:
ibus-mozc is disabled after step 4.

Additional info:
Here is a quick and initial patch for ibus-mozc 1.11.1522.102.
https://code.google.com/p/mozc/issues/detail?id=199#c1

Comment 1 Fedora Update System 2013-10-08 11:34:41 UTC
mozc-1.11.1522.102-3.fc19 has been submitted as an update for Fedora 19.
https://admin.fedoraproject.org/updates/mozc-1.11.1522.102-3.fc19

Comment 2 Fedora Update System 2013-10-10 00:52:08 UTC
Package mozc-1.11.1522.102-3.fc19:
* should fix your issue,
* was pushed to the Fedora 19 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing mozc-1.11.1522.102-3.fc19'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2013-18600/mozc-1.11.1522.102-3.fc19
then log in and leave karma (feedback).

Comment 3 Fedora Update System 2013-10-10 02:45:46 UTC
mozc-1.11.1522.102-3.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/mozc-1.11.1522.102-3.fc20

Comment 4 Fedora Update System 2013-10-19 09:06:23 UTC
mozc-1.11.1522.102-3.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2013-11-10 07:28:56 UTC
mozc-1.11.1522.102-3.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.