Bug 1046839 (CVE-2013-7221)

Summary: CVE-2013-7221 gnome-shell: run command dialog visible above screen locker
Product: [Other] Security Response Reporter: Huzaifa S. Sidhpurwala <huzaifas>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: fmuellner, otaylor, pfrields, samkraju, vkrizan, walters
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-12-28 02:46:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1030960    

Description Huzaifa S. Sidhpurwala 2013-12-27 05:07:26 UTC
In Fedora 19, the "Enter the Command" dialog box is visible even after you lock the screen, so anyone can write the commands in the box and execute them over a locked screen.

The issue is still to be fixed and tested on Gnome Fedora 18 and 19 machines. KDE version were not found to be affected.

This flaw is split from bug 1030431

Comment 1 Huzaifa S. Sidhpurwala 2013-12-27 05:23:55 UTC
Upstream bug: 
https://bugzilla.gnome.org/show_bug.cgi?id=708313

Upstream patch:
https://git.gnome.org/browse/gnome-shell/commit/js/ui/main.js?id=efdf1ff755943fba1f8a9aaeff77daa3ed338088

This issue has been addressed in gnome-shell-3.10.0

Comment 2 Huzaifa S. Sidhpurwala 2013-12-27 05:27:08 UTC
The patch for this issue was backported to Fedora-19 via the following commit:

http://pkgs.fedoraproject.org/cgit/gnome-shell.git/commit/?h=f19&id=dfe68f1744ae3235df60a0be7a900b9279c7f5db 

It is available by upgrading to gnome-shell-3.8.4-3.fc19

Fedora-20 ships gnome-shell-3.10.2 and therefore is not affected.

Comment 4 Huzaifa S. Sidhpurwala 2013-12-28 02:46:36 UTC
This issue has been assigned CVE-2013-7221 as per:

http://www.openwall.com/lists/oss-security/2013/12/27/8